Sploitus

CVE-2020-0688

28 known exploits for CVE-2020-0688

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.

Affected products
Asp.Net, Exchange Server
Microsoft Exchange Server
= 2010, 2013, 2016, 2019
CVSS 2.0
9.0 HIGH
CVSS 3.1
8.8 HIGH
EPSS
100.0% (100th percentile)
Weakness
CWE-287
NVD status
Analyzed
Published
2020-02-11
CVE-2020-0688 at NVD
Authoritative description, scoring and affected products

28 known exploits for CVE-2020-0688

Proof-of-concept code and exploit modules indexed by Sploitus

Exploit for Improper Authentication in Microsoft
2025-07-27 mirrors_RidterGITEE
Exploit for Improper Authentication in Microsoft
2025-07-06 mirrors_zcgonvhGITEE
Exploit for Improper Authentication in Microsoft
2024-05-09 W01fh4ckerGITHUB
Exploit for Improper Authentication in Microsoft
2021-01-04 MrTizGITHUB
Exploit for Improper Authentication in Microsoft
2020-10-29 SLSteffGITHUB
Exploit for Improper Authentication in Microsoft
2020-10-23 zyn3rgyGITHUB
Exploit for Improper Authentication in Microsoft
2020-08-17 murataydemirGITHUB
Background Intelligent Transfer Service Privilege Escalation Exploit
2020-06-12 metasploitZDTRuby
Background Intelligent Transfer Service CVE-2020-0787 - Privilege Escalation
2020-06-12 0daydb.comUNKNOWNRuby
Exploit for Improper Authentication in Microsoft
2020-06-12 w4fz5uck5GITHUB
Background Intelligent Transfer Service Privilege Escalation
2020-06-11 itm4nPACKETSTORMRuby
Exploit for Improper Authentication in Microsoft
2020-04-22 ktpdproGITHUB
Exploit for Improper Authentication in Microsoft
2020-03-19 cert-lvGITHUB
Exploit for Improper Authentication in Microsoft
2020-03-07 kevin66654GITEE
Exchange Control Panel Viewstate Deserialization Exploit
2020-03-05 metasploitZDTRuby
Exchange Control Panel - Viewstate Deserialization (Metasploit)
2020-03-05 MetasploitEXPLOITDBRuby
Exchange Control Panel Viewstate Deserialization
2020-03-04 Spencer McIntyrePACKETSTORMRuby
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution Exploit
2020-03-02 PhotubiasZDT
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
2020-03-02 PhotubiasEXPLOITPACK
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
2020-03-02 PhotubiasEXPLOITDB
Microsoft Exchange 2019 15.2.221.12 Remote Code Execution
2020-03-02 PhotubiasPACKETSTORM
Exploit for Improper Authentication in Microsoft
2020-03-01 zcgonvhGITHUB
Exploit for Improper Authentication in Microsoft
2020-02-28 onSec-frGITHUB
Exploit for Improper Authentication in Microsoft
2020-02-27 RidterGITHUB
Exploit for Improper Authentication in Microsoft
2020-02-27 Yt1g3rGITHUB
Exploit for Improper Authentication in Microsoft
2020-02-25 random-robbieGITHUB
Immunity Canvas: OWA_RCE
2020-02-11 Immunity CanvasCANVAS
Exchange Control Panel ViewState Deserialization
2020-02-11 Spencer McIntyreMETASPLOITRuby