logo

Microsoft Exchange Control Panel (ECP) Vulnerability CVE-2020-0688 Exploited

ID: a8fcacf6-2658-5b36-8a06-47ac3a012fd8

STIX ID: report--a8fcacf6-2658-5b36-8a06-47ac3a012fd8

Feed Name: Volexity Blog

Threat Score
75/100

Date Published: 2020-03-06

Date Updated: 2026-05-01

...
...

Volexity outlines active exploitation of CVE-2020-0688 — a Microsoft Exchange ECP/ViewState RCE — observed being abused by APT actors to run commands, deploy webshells, and execute in-memory post-exploitation tools; the report provides detection guidance (ECP ServerException logs, Application Event Log Event ID 4, IIS logs, likely webshell locations), notes credential brute-force activity against Exchange Web Services, and recommends immediate patching, restricting ECP access, and credential hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.