CISA Known Exploited Vulnerability

CVE-2020-0688 Ransomware

Microsoft · Exchange Server

Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-287
Ransomware Known

CISA description

Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.

Required action

Apply updates per vendor instructions.