CVE-2020-0688: Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
Other sources
Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-0688?
CVE-2020-0688 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Microsoft Exchange Server.
How severe is CVE-2020-0688?
CVE-2020-0688 has a severity rating of 8.8 out of 10, which is considered critical.
Which software products are affected by CVE-2020-0688?
CVE-2020-0688 affects Microsoft Exchange Server 2010 (SP3 Rollup 30), 2013 (Cumulative Update 23), 2016 (Cumulative Update 14 or 15), and 2019 (Cumulative Update 3 or 4).
Is authentication required to exploit CVE-2020-0688?
Yes, authentication is required to exploit CVE-2020-0688.
How can I fix CVE-2020-0688?
To fix CVE-2020-0688, apply the necessary security updates provided by Microsoft for your specific version of Microsoft Exchange Server.