CVE-2020-0688

Alta8.8Pubblicata il 11 febbraio 2020

Esiste una vulnerabilità di esecuzione di codice da remoto nel software Microsoft Exchange quando il software non gestisce correttamente gli oggetti in memoria, nota come "Microsoft Exchange Memory Corruption Vulnerability".

Sfruttata attivamente

  • Nel catalogo CISA delle vulnerabilità sfruttate dal 3 nov 2021
  • Le agenzie federali statunitensi devono correggerla entro il 3 mag 2022 (direttiva BOD 22-01)
  • Primo attacco osservato 27 giorni dopo la divulgazione
  • Usata in campagne ransomware

Apply updates per vendor instructions.

Fonte: CISA KEV · 28 lug 2026 31 mar 2026 16 mar 2026 11 mar 2026 9 mar 2026 3 mar 2026

Punteggio CVSS8.8 / 10CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Tipo di debolezza (CWE)CWE-287, CWE-287
Vendormicrosoft

Prodotti coinvolti

VendorProdottoVersioni
microsoftexchange server2010

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

La descrizione tecnica è una nostra traduzione del testo originale NVD, in inglese.

Database CVE