{
  "id": "CVE-2020-0688",
  "url": "https://spydr.io/cve/CVE-2020-0688",
  "published": "2020-02-11T22:15:15.900Z",
  "modified": "2026-06-17T02:46:21.387Z",
  "score": 8.8,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.99962,
  "epss_percentile": 0.99976,
  "exploited": true,
  "kev": {
    "added": "2021-11-03",
    "due": "2022-05-03",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Known",
    "name": "Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-0688"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "Microsoft"
  ],
  "products": [
    "Microsoft Exchange Server 2013",
    "Microsoft Exchange Server 2019 Cumulative Update 3",
    "Microsoft Exchange Server 2016 Cumulative Update 14",
    "Microsoft Exchange Server 2016 Cumulative Update 15",
    "Microsoft Exchange Server 2019 Cumulative Update 4",
    "Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30"
  ],
  "cwes": [
    "CWE-287"
  ],
  "description": "A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 8.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/156592/Microsoft-Exchange-2019-15.2.221.12-Remote-Code-Execution.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://packetstormsecurity.com/files/156620/Exchange-Control-Panel-Viewstate-Deserialization.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0688",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://www.zerodayinitiative.com/advisories/ZDI-20-258/",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0688",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2020-0688",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
