First published: Tue May 10 2022(Updated: )
Microsoft Exchange Server Elevation of Privilege Vulnerability.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2013-cumulative_update_23 | |
Microsoft Exchange Server | =2016-cumulative_update_22 | |
Microsoft Exchange Server | =2016-cumulative_update_23 | |
Microsoft Exchange Server | =2019-cumulative_update_11 | |
Microsoft Exchange Server | =2019-cumulative_update_12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21978 is a vulnerability in Microsoft Exchange Server that allows an attacker to elevate their privileges.
CVE-2022-21978 has a severity rating of 8.2, which is considered high.
CVE-2022-21978 affects Microsoft Exchange Server 2013 with Cumulative Update 23, 2016 with Cumulative Update 22 or 23, and 2019 with Cumulative Update 11 or 12.
An attacker can exploit CVE-2022-21978 by sending a specially crafted request to a vulnerable Exchange server.
Yes, Microsoft has released security updates to address CVE-2022-21978. It is recommended to install the latest updates as soon as possible.