CVE-2022-21980: Microsoft Exchange Server Elevation of Privilege Vulnerability
Published Aug 9, 2022
·Updated
Microsoft Exchange Server Elevation of Privilege Vulnerability
Affected Software
12 affected componentsFixes available
Microsoft Exchange Server 2016=23
Microsoft Exchange Server 2016=22
Microsoft Exchange Server 2013=23
Microsoft Exchange Server 2019=11
Microsoft Exchange Server 2019=12
Microsoft Exchange server=2019 CU14
Microsoft Exchange server
Microsoft Exchange server=2013-cumulative_update_23
Microsoft Exchange server=2016-cumulative_update_22
Microsoft Exchange server=2016-cumulative_update_23
Microsoft Exchange server=2019-cumulative_update_11
Microsoft Exchange server=2019-cumulative_update_12
Event History
Aug 9, 2022
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·07:47 PM
Data Sourced
via MITRE·07:47 PM
DescriptionSeverity
Feb 14, 2024
News Published
via BleepingComputer·05:34 PM
News Published
via BleepingComputer·05:35 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is CVE-2022-21980?
CVE-2022-21980 is a vulnerability in Microsoft Exchange Server that allows an attacker to elevate their privileges.
2
How severe is CVE-2022-21980?
CVE-2022-21980 is classified as a critical vulnerability with a severity value of 8 out of 10.
3
Which versions of Microsoft Exchange Server are affected by CVE-2022-21980?
Microsoft Exchange Server 2016 versions 22 and 23, Microsoft Exchange Server 2013 version 23, and Microsoft Exchange Server 2019 versions 11 and 12 are affected by CVE-2022-21980.
4
How can I fix CVE-2022-21980?
To fix CVE-2022-21980, you should apply the relevant patches provided by Microsoft Exchange Server.
5
Where can I find more information about CVE-2022-21980?
You can find more information about CVE-2022-21980 on the Microsoft Security Response Center website.