← KEV catalog
CISA known exploited vulnerability

CVE-2020-0688

Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability

SOURCE FACT

Microsoft · Exchange Server

Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2020-0688

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?