Advisory 2020-008: Copy-Paste ... - ACSC | Cyber.gov.au

The ACSC has also identified the exploitation of VIEWSTATE handling on Microsoft Exchange servers in the form of CVE-2020-0688. The malicious actor combined stolen legitimate credentials and the presence of the default Microsoft Exchange validationKey and decryptionKey to exploit this vulnerability to execute arbitrary commands. ................
................