CVE-2020-0688
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
- Affected products
- Asp.Net, Exchange Server
- Microsoft Exchange Server
- = 2010, 2013, 2016, 2019
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-287
- NVD status
- Analyzed
- Published
- 2020-02-11
CVE-2020-0688 at NVD
28 known exploits for CVE-2020-0688
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Improper Authentication in Microsoft
Exploit for Improper Authentication in Microsoft
Exploit for Improper Authentication in Microsoft
Exploit for Improper Authentication in Microsoft
Exploit for Improper Authentication in Microsoft
Exploit for Improper Authentication in Microsoft
Exploit for Improper Authentication in Microsoft
Background Intelligent Transfer Service Privilege Escalation Exploit
Background Intelligent Transfer Service CVE-2020-0787 - Privilege Escalation
Exploit for Improper Authentication in Microsoft
Background Intelligent Transfer Service Privilege Escalation
Exploit for Improper Authentication in Microsoft
Exploit for Improper Authentication in Microsoft
Exploit for Improper Authentication in Microsoft
Exchange Control Panel Viewstate Deserialization Exploit
Exchange Control Panel - Viewstate Deserialization (Metasploit)
Exchange Control Panel Viewstate Deserialization
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution Exploit
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
Microsoft Exchange 2019 15.2.221.12 Remote Code Execution
Exploit for Improper Authentication in Microsoft
Exploit for Improper Authentication in Microsoft
Exploit for Improper Authentication in Microsoft
Exploit for Improper Authentication in Microsoft
Exploit for Improper Authentication in Microsoft
Immunity Canvas: OWA_RCE
Exchange Control Panel ViewState Deserialization