CVE-2020-0688
Esiste una vulnerabilità di esecuzione di codice da remoto nel software Microsoft Exchange quando il software non gestisce correttamente gli oggetti in memoria, nota come "Microsoft Exchange Memory Corruption Vulnerability".
Sfruttata attivamente
- Nel catalogo CISA delle vulnerabilità sfruttate dal 3 nov 2021
- Le agenzie federali statunitensi devono correggerla entro il 3 mag 2022 (direttiva BOD 22-01)
- Primo attacco osservato 27 giorni dopo la divulgazione
- Usata in campagne ransomware
Apply updates per vendor instructions.
Fonte: CISA KEV · 28 lug 2026 31 mar 2026 16 mar 2026 11 mar 2026 9 mar 2026 3 mar 2026
Punteggio CVSS8.8 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HTipo di debolezza (CWE)CWE-287, CWE-287
Vendormicrosoft
Prodotti coinvolti
| Vendor | Prodotto | Versioni |
|---|---|---|
| microsoft | exchange server | 2010 |
Articoli correlati
This product uses the NVD API but is not endorsed or certified by the NVD.
La descrizione tecnica è una nostra traduzione del testo originale NVD, in inglese.
