#VU25226 Deserialization of untrusted data in Microsoft Exchange Server - CVE-2020-0688
Published: February 11, 2020 / Updated: August 3, 2023
Microsoft Exchange Server
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary on the system.
The vulnerability exists due to an input validation error within the Microsoft Exchange OCP interface when processing VIEWSTATE data. A remote authenticated attacker can send a specially crafted HTTP request to a vulnerable Exchange server and execute arbitrary code on the target system.
Note, this vulnerability is being actively exploited in the wild.