Description
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
In plain language
AI Act nowCVE-2020-0688 is a Microsoft Exchange Server flaw that can let an attacker take over the Exchange server over the network, and a typical small business running Exchange Server should act urgently if it’s not fully patched.
CVE-2020-0688 is a remote code execution issue in Microsoft Exchange when the software fails to properly handle objects in memory (CWE-287), allowing attackers to run code on the server; it has confirmed real-world use in ransomware campaigns (CISA KEV).
What to do now
- Check whether your business uses Microsoft Exchange Server (on-prem) and confirm which Exchange version and cumulative update you’re running.
- Compare your installed Exchange build against Microsoft’s guidance for CVE-2020-0688 and determine whether you are behind the fixed updates.
- Update Microsoft Exchange Server immediately by applying the Microsoft security update(s) referenced for CVE-2020-0688.
- If you can’t patch right away, restrict external access to Exchange as an interim step and block direct internet reachability to Exchange endpoints while you plan the update.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Кибершпионы NightEagle нацелились на производственные и строительные предприятия в Россииru-ru·Хакер (xakep.ru)· Exploited Microsoft Exchange NightEagle
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipersen·The Hacker News· Exploited Microsoft Exchange Server NightEagle
- NightEagle APT targets Russian organizationsen-us·Kaspersky Securelist· Incident Exchange Server NightEagle
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2020-0688 and every CVE in our database. Create a free account — no credit card required.
Create Free Account