CVE-2020-0688 — Microsoft Exchange Validation Key Remote Code Execution Vulnerability
Executive Summary
A remote code execution vulnerability exists in Microsoft Exchange Server when the server fails to properly create unique keys at install time. Knowledge of a the validation key allows an authenticated user with a mailbox to pass arbitrary objects to be deserialized by the web application, which runs as SYSTEM. The security update addresses the vulnerability by correcting how Microsoft Exchange creates the keys during install.
Overview
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30 | 4536989 (Security Update) |
Important | Remote Code Execution | Maybe |
| Microsoft Exchange Server 2013 Cumulative Update 23 | 4536988 (Security Update) |
Important | Remote Code Execution | Maybe |
| Microsoft Exchange Server 2016 Cumulative Update 14 | 4536987 (Security Update) |
Important | Remote Code Execution | Maybe |
| Microsoft Exchange Server 2016 Cumulative Update 15 | 4536987 (Security Update) |
Important | Remote Code Execution | Maybe |
| Microsoft Exchange Server 2019 Cumulative Update 3 | 4536987 (Security Update) |
Important | Remote Code Execution | Maybe |
| Microsoft Exchange Server 2019 Cumulative Update 4 | 4536987 (Security Update) |
Important | Remote Code Execution | Maybe |
Patches
| Article | Type | Restart |
|---|---|---|
4536989 |
Security Update | Maybe |
4536988 |
Security Update | Maybe |
4536987 |
Security Update | Maybe |
Exploits & PoC
15 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| zcgonvh/CVE-2020-0688 | 354 | 2020-03-01 | Exploit and detect tools for CVE-2020-0688 |
| Ridter/cve-2020-0688 | 328 | 2020-02-27 | cve-2020-0688 |
| random-robbie/cve-2020-0688 | 163 | 2020-02-25 | cve-2020-0688 |
| Yt1g3r/CVE-2020-0688_EXP | 144 | 2020-02-27 | CVE-2020-0688_EXP Auto trigger payload & encrypt method |
| Jumbo-WJB/CVE-2020-0688 | 66 | 2020-02-26 | CVE-2020-0688 - Exchange |
| onSec-fr/CVE-2020-0688-Scanner | 37 | 2020-02-28 | Quick tool for checking CVE-2020-0688 on multiple hosts with a non-intrusive method. |
| w4fz5uck5/cve-2020-0688-webshell-upload-technique | 23 | 2020-06-12 | cve-2020-0688 UNIVERSAL Python implementation utilizing ASPX webshell for command output |
| MrTiz/CVE-2020-0688 | 21 | 2021-01-04 | Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys |
| W01fh4cker/CVE-2020-0688-GUI | 16 | 2024-05-09 | GUI Exploit Tool for CVE-2020-0688(Microsoft Exchange default MachineKeySection deserialize vulnerability) |
| ravinacademy/CVE-2020-0688 | 11 | 2020-03-31 | Exploitation Script for CVE-2020-0688 "Microsoft Exchange default MachineKeySection deserialize vulnerability" |
| zyn3rgy/ecp_slap | 11 | 2020-10-23 | CVE-2020-0688 PoC |
| youncyb/CVE-2020-0688 | 10 | 2020-02-28 | CVE-2020-0688 |
| cert-lv/CVE-2020-0688 | 8 | 2020-03-19 | Vulnerability scanner for CVE-2020-0688 |
| justin-p/PSForgot2kEyXCHANGE | 5 | 2020-03-04 | PoC for Forgot2kEyXCHANGE (CVE-2020-0688) written in PowerShell |
| murataydemir/CVE-2020-0688 | 4 | 2020-08-17 | [CVE-2020-0688] Microsoft Exchange Server Fixed Cryptographic Key Remote Code Execution (RCE) |
Detection Rules
Detection availableCommunity detection & vulnerability-scanning rules aggregated from Sigma and Nuclei templates. Validate and tune to your environment before deploying.
Sigma rules 3
Acknowledgments
Anonymous working with Trend Micro's Zero Day Initiative