CVE-2022-21978: Microsoft Exchange Server Elevation of Privilege Vulnerability
Published May 10, 2022
·Updated
Microsoft Exchange Server Elevation of Privilege Vulnerability.
Affected Software
10 affected componentsFixes available
Microsoft Exchange Server 2016=23
Microsoft Exchange Server 2016=22
Microsoft Exchange Server 2013=23
Microsoft Exchange Server 2019=11
Microsoft Exchange Server 2019=12
Microsoft Exchange server=2013-cumulative_update_23
Microsoft Exchange server=2016-cumulative_update_22
Microsoft Exchange server=2016-cumulative_update_23
Microsoft Exchange server=2019-cumulative_update_11
Microsoft Exchange server=2019-cumulative_update_12
Remediation
Event History
May 10, 2022
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-21978?
CVE-2022-21978 is a vulnerability in Microsoft Exchange Server that allows an attacker to elevate their privileges.
2
How severe is CVE-2022-21978?
CVE-2022-21978 has a severity rating of 8.2, which is considered high.
3
Which versions of Microsoft Exchange Server are affected by CVE-2022-21978?
CVE-2022-21978 affects Microsoft Exchange Server 2013 with Cumulative Update 23, 2016 with Cumulative Update 22 or 23, and 2019 with Cumulative Update 11 or 12.
4
How can an attacker exploit CVE-2022-21978?
An attacker can exploit CVE-2022-21978 by sending a specially crafted request to a vulnerable Exchange server.
5
Is there a fix available for CVE-2022-21978?
Yes, Microsoft has released security updates to address CVE-2022-21978. It is recommended to install the latest updates as soon as possible.