First published: Tue Feb 11 2020(Updated: )
Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2010-sp3_rollup_30 | |
Microsoft Exchange Server | =2013-cumulative_update_23 | |
Microsoft Exchange Server | =2016-cumulative_update_14 | |
Microsoft Exchange Server | =2016-cumulative_update_15 | |
Microsoft Exchange Server | =2019-cumulative_update_3 | |
Microsoft Exchange Server | =2019-cumulative_update_4 | |
Microsoft Exchange |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-0688 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Microsoft Exchange Server.
CVE-2020-0688 has a severity rating of 8.8 out of 10, which is considered critical.
CVE-2020-0688 affects Microsoft Exchange Server 2010 (SP3 Rollup 30), 2013 (Cumulative Update 23), 2016 (Cumulative Update 14 or 15), and 2019 (Cumulative Update 3 or 4).
Yes, authentication is required to exploit CVE-2020-0688.
To fix CVE-2020-0688, apply the necessary security updates provided by Microsoft for your specific version of Microsoft Exchange Server.