CVE-2022-23277: Microsoft Exchange Server Remote Code Execution Vulnerability
Published Mar 8, 2022
·Updated
Microsoft Exchange Server Remote Code Execution Vulnerability
Affected Software
10 affected componentsFixes available
Microsoft Exchange Server 2016=21
Microsoft Exchange Server 2016=22
Microsoft Exchange Server 2013=23
Microsoft Exchange Server 2019=11
Microsoft Exchange Server 2019=10
Microsoft Exchange server=2013-cumulative_update_23
Microsoft Exchange server=2016-cumulative_update_21
Microsoft Exchange server=2016-cumulative_update_22
Microsoft Exchange server=2019-cumulative_update_10
Microsoft Exchange server=2019-cumulative_update_11
Event History
Mar 8, 2022
CVE Published
08:00 AM
Data Sourced
08:00 AM
DescriptionSeverityWeakness
Mar 9, 2022
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-23277?
CVE-2022-23277 is a Microsoft Exchange Server Remote Code Execution Vulnerability.
2
How severe is CVE-2022-23277?
CVE-2022-23277 has a severity rating of critical.
3
Which versions of Microsoft Exchange Server are affected by CVE-2022-23277?
Microsoft Exchange Server 2013 (Cumulative Update 23), 2016 (Cumulative Update 21, Cumulative Update 22), and 2019 (Cumulative Update 10, Cumulative Update 11) are affected by CVE-2022-23277.
4
What is the remedy for CVE-2022-23277?
The remedy for CVE-2022-23277 is to install the relevant security patch provided by Microsoft.
5
Where can I find more information about CVE-2022-23277?
You can find more information about CVE-2022-23277 on the Microsoft Security Response Center website.