Deserialization of untrusted data in Microsoft Exchange Server - CVE-2020-0688
Published: February 11, 2020 / Updated: August 3, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary on the system.
The vulnerability exists due to an input validation error within the Microsoft Exchange OCP interface when processing VIEWSTATE data. A remote authenticated attacker can send a specially crafted HTTP request to a vulnerable Exchange server and execute arbitrary code on the target system.
Note, this vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2020-0688
Links to Public Exploits and PoC-codes
- Exploit #9222 - CVE-2020-0688-Exchange2010 (CVE-2020-0688 modified exploit for Exchange 2010 ) (August 3, 2023)
- Exploit #8498 - CVE-2020-0688-Python3 (Exploit updated to use Python 3.) (October 19, 2022)
- Exploit #7791 - CVE-2020-0688 (CVE-2020-0688_Microsoft Exchange default MachineKeySection deserialize vulnerability) (May 12, 2022)
- Exploit #5756 - Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution (June 17, 2021)
- Exploit #5747 - Exchange Control Panel - Viewstate Deserialization (Metasploit) (June 17, 2021)
- Exploit #5537 - CVE-2020-0688 (Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys) (June 6, 2021)
- Exploit #4991 - CVE-2020-0688 (Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys) (January 5, 2021)
- Exploit #4789 - CVE-2020-0688-Scanner (Scans for Microsoft Exchange Versions with masscan) (November 3, 2020)
- Exploit #4756 - ecp_slap (CVE-2020-0688 PoC) (October 28, 2020)
- Exploit #4685 - cve_2020_0688 () (October 10, 2020)
- Exploit #3039 - cve-2020-0688-webshell-upload-technique (cve-2020-0688 UNIVERSAL Python implementation utilizing ASPX webshell for command output) (June 19, 2020)
- Exploit #2937 - CVE-2020-0688 (PoC RCE Reverse Shell for CVE-2020-0688) (June 3, 2020)
- Exploit #2886 - CVE-2020-0688 (Vulnerability scanner for CVE-2020-0688) (June 3, 2020)
- Exploit #2263 - Exploit_CVE-2020-0688 (CVE-2020-0688 "Microsoft Exchange default MachineKeySection deserialize vulnerability" ) (April 5, 2020)
- Exploit #2247 - CVE-2020-0688 (Exploitation Script for CVE-2020-0688 "Microsoft Exchange default MachineKeySection deserialize vulnerability") (March 31, 2020)
- Exploit #2215 - CVE-2020-0688 (CVE-2020-0688) (March 18, 2020)
- Exploit #309 - cve-2020-0688 (cve-2020-0688) (March 18, 2020)
- Exploit #1476 - Exchange Control Panel Viewstate Deserialization (March 18, 2020)
- Exploit #317 - PSForgot2kEyXCHANGE (PoC for Forgot2kEyXCHANGE (CVE-2020-0688) written in PowerShell) (March 18, 2020)
- Exploit #316 - CVE-2020-0688 (Exploit and detect tools for CVE-2020-0688) (March 18, 2020)
- Exploit #315 - CVE-2020-0688-Scanner (Quick tool for checking CVE-2020-0688 on multiple hosts with a non-intrusive method.) (March 18, 2020)
- Exploit #314 - CVE-2020-0688 (Exchange Scanner CVE-2020-0688) (March 18, 2020)
- Exploit #313 - cve-2020-0688 (I made this script for conducting CVE-2020-0688 more rapidly. It helps to improve checking the vuln, reducing hugely steps for that) (March 18, 2020)
- Exploit #312 - CVE-2020-0688_EXP (CVE-2020-0688_EXP Auto trigger payload & encrypt method) (March 18, 2020)
- Exploit #311 - CVE-2020-0688 (CVE-2020-0688 - Exchange) (March 18, 2020)
- Exploit #310 - cve-2020-0688 (cve-2020-0688) (March 18, 2020)