NVD disclosure day

Published threat advisories for February 11, 2020

CVE advisoryKnown Exploit

CVE-2020-0688

Microsoft Exchange Server Remote Code Execution Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Microsoft Exchange Server allows for remote code execution due to improper memory object handling. This can lead to unauthorized system control and potential data breaches, posing a business risk to affected organizations. Exploitation requires network access and an authenticated user.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2020-0674

Internet Explorer Scripting Engine Memory Corruption Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A scripting engine memory corruption vulnerability in Internet Explorer can allow attackers to execute code. This impacts organizations using the browser, posing a risk of unauthorized access and operational disruption. Exploitation requires user interaction with a malicious website.

• CISA KEV