CVE-2020-0688
KEV RANSOMWAREHIGH 9.0EPSS 100.0%
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 99.97% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Published
- 2020-02-11
- Updated
- 2025-10-21
Proof-of-concept exploits (29)
- http://packetstormsecurity.com/files/156592/Microsoft-Exchange-2019-15.2.221.12-Remote-Co…
- http://packetstormsecurity.com/files/156620/Exchange-Control-Panel-Viewstate-Deserializat…
- 1337-llama/CVE-2020-0688-Python32★ · 2023-10-26
- 7heKnight/CVE-2020-06880★ · 2022-06-03
- Jumbo-WJB/CVE-2020-068866★ · 2020-02-27
- Ken-Abruzzi/cve_2020_06880★ · 2020-10-10
- LostZX/ExchangeLearn10★ · 2023-01-24
- MrTiz/CVE-2020-068821★ · 2021-06-06
- Ridter/cve-2020-0688328★ · 2023-07-04
- TheKickPuncher/CVE-2020-0688-Python32★ · 2023-10-26
- W01fh4cker/CVE-2020-0688-GUI16★ · 2024-05-09
- Yt1g3r/CVE-2020-0688_EXP144★ · 2020-02-27
- cert-lv/CVE-2020-06888★ · 2020-03-19
- chudamax/CVE-2020-0688-Exchange20101★ · 2023-08-02
- justin-p/PSForgot2kEyXCHANGE5★ · 2020-03-05
- ktpdpro/CVE-2020-06883★ · 2020-04-22
- mahyarx/Exploit_CVE-2020-06882★ · 2020-04-05
- murataydemir/CVE-2020-06884★ · 2020-08-29
- random-robbie/cve-2020-0688163★ · 2020-02-26
- ravinacademy/CVE-2020-068811★ · 2020-04-01
- righter83/CVE-2020-06882★ · 2021-09-10
- seclib/Active-Directory-Exploitation1★ · 2024-07-29
- truongtn/cve-2020-06881★ · 2025-01-14
- truongtn/python-FUD0★ · 2025-01-14
- tvdat20004/CVE-2020-06880★ · 2025-08-04
- w4fz5uck5/cve-2020-0688-webshell-upload-technique23★ · 2023-09-12
- youncyb/CVE-2020-068810★ · 2020-02-28
- zcgonvh/CVE-2020-0688354★ · 2020-03-21
- zyn3rgy/ecp_slap11★ · 2024-11-19