PT-2020-1715 · Microsoft · Exchange Server+1

Published

2020-02-11

·

Updated

2026-06-08

·

CVE-2020-0688

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server (affected versions not specified)
Description A remote code execution issue exists in Microsoft Exchange Server due to the failure to properly create unique keys during installation. This flaw, also referred to as a memory corruption issue, stems from deficiencies in the deserialization mechanism. An authenticated user with a mailbox who possesses the validation key can pass arbitrary objects to be deserialized by the web application, which operates with SYSTEM privileges. Real-world exploitation has been observed in Asia, targeting government agencies and high-tech companies through a sophisticated backdoor named GhostContainer. This malware uses the App Web Container 1.dll file as a container, employing a Stub class for command parsing and a App Web 843e75cf5b63 class as a web-proxy loader. It evades detection by overwriting memory addresses in amsi.dll and ntdll.dll to bypass the Antimalware Scan Interface (AMSI) and Windows event logging.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Improper Authentication

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00948
CVE-2020-0688
ZDI-20-258

Affected Products

Asp.Net
Exchange Server