RULE(RULE ID:324402)

Rule General Information
Release Date: 2020-03-25
Rule Name: Microsoft Exchange Server Fixed Cryptographic Key Remote Code Execution Vulnerability (CVE-2020-0688)
Severity:
CVE ID:
Rule Protection Details
Description: A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Others
Reference: http://packetstormsecurity.com/files/156592/Microsoft-Exchange-2019-15.2.221.12-Remote-Code-Execution.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0688
http://packetstormsecurity.com/files/156620/Exchange-Control-Panel-Viewstate-Deserialization.html
ZeroDayInitiative:ZDI-20-258
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-0688