Detecting CVE-2020-0688 Remote Code Execution…
ID: 28a8c45e-b794-5b23-9658-bfa5290d32aa
STIX ID: report--28a8c45e-b794-5b23-9658-bfa5290d32aa
Feed Name: TrustedSec blog
**Executive Summary:** This report documents CVE-2020-0688, a critical Microsoft Exchange Server remote code execution due to a shared validation key allowing crafted __VIEWSTATE payloads to execute arbitrary commands as SYSTEM; TrustedSec validated public proof-of-concept exploits and the report provides exploitation steps, vulnerable endpoints, process execution evidence (w3wp.exe spawning calc.exe as SYSTEM), IIS and event log examples, and Exchange log locations to support detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
