CVE-2022-21846: Microsoft Exchange Server Remote Code Execution Vulnerability
Published Jan 11, 2022
·Updated
Microsoft Exchange Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-21855, CVE-2022-21969.
Affected Software
10 affected componentsFixes available
Microsoft Exchange Server 2016=21
Microsoft Exchange Server 2016=22
Microsoft Exchange Server 2013=23
Microsoft Exchange Server 2019=10
Microsoft Exchange Server 2019=11
Microsoft Exchange server=2013-cumulative_update_23
Microsoft Exchange server=2016-cumulative_update_21
Microsoft Exchange server=2016-cumulative_update_22
Microsoft Exchange server=2019-cumulative_update_10
Microsoft Exchange server=2019-cumulative_update_11
Remediation
Event History
Jan 11, 2022
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-21846?
CVE-2022-21846 is a remote code execution vulnerability in Microsoft Exchange Server.
2
How severe is CVE-2022-21846?
CVE-2022-21846 is classified as critical with a severity value of 9.
3
Which versions of Microsoft Exchange Server are affected by CVE-2022-21846?
The versions of Microsoft Exchange Server affected by CVE-2022-21846 are 2013 cumulative update 23, 2016 cumulative update 21 and 22, and 2019 cumulative update 10 and 11.
4
How can I fix CVE-2022-21846?
To fix CVE-2022-21846, you should apply the relevant security updates provided by Microsoft.
5
Where can I find more information about CVE-2022-21846?
You can find more information about CVE-2022-21846 on the official Microsoft Security Guidance Advisory page: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-21846