'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2020-0688: Microsoft Exchange Server Remote Code Execution Vulnerability
Severity:high
CVE ID:CVE-2020-0688
| Descripiton:
|
Microsoft Exchange Server is a set of e-mail service programs of Microsoft Corporation of the United States. It provides mail access, storage, forwarding, voice mail, mail filtering and other functions. A trust management issue vulnerability exists in Microsoft Exchange Server that arises from a program's inability to properly handle objects in memory. An attacker could exploit the vulnerability to run arbitrary code in the context of a system user via a specially crafted email. The following products and versions are affected: Microsoft Exchange Server 2010, Microsoft Exchange Server 2013, Microsoft Exchange Server 2016, Microsoft Exchange Server 2019. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.