VID |
18125 |
Severity |
40 |
Port |
25 |
Protocol |
TCP |
Class |
SMTP |
Detailed Description |
CVE-2020-0688 is a critical vulnerability in Microsoft Exchange due to use of static keys. Although exploitation requires valid credentials (at an email user level) and the risk of mass-exploitation is low, this vulnerability might be very useful in targeted attacks as it leads to SYSTEM level RCE.
* References: https://github.com/cert-lv/CVE-2020-0688 http://packetstormsecurity.com/files/156592/Microsoft-Exchange-2019-15.2.221.12-Remote-Code-Execution.html http://packetstormsecurity.com/files/156620/Exchange-Control-Panel-Viewstate-Deserialization.html https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0688 https://www.zerodayinitiative.com/advisories/ZDI-20-258/
* Platforms Affected: Upgrade Exchange Server 2013(15.0.1497.6 before), 2016( 15.1.1847.7, 15.1.1913.7 before) 2019(15.2.464.11, 15.2.529.8 before) |
Recommendation |
Upgrade Exchange Server 2013(15.0.1497.6 or later), 2016( 15.1.1847.7, 15.1.1913.7 or later) 2019(15.2.464.11, 15.2.529.8 or later) |
Related URL |
CVE-2020-0688 (CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|