CVE-2022-24463: Microsoft Exchange Server Spoofing Vulnerability
Published Mar 8, 2022
·Updated
Microsoft Exchange Server Spoofing Vulnerability
Affected Software
8 affected componentsFixes available
Microsoft Exchange Server 2016=22
Microsoft Exchange Server 2016=21
Microsoft Exchange Server 2019=10
Microsoft Exchange Server 2019=11
Microsoft Exchange Server=2016-cumulative_update_21
Microsoft Exchange Server=2016-cumulative_update_22
Microsoft Exchange Server=2019-cumulative_update_10
Microsoft Exchange Server=2019-cumulative_update_11
Event History
Mar 8, 2022
CVE Published
08:00 AM
Data Sourced
08:00 AM
DescriptionSeverityWeakness
Mar 9, 2022
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-24463?
CVE-2022-24463 is a vulnerability in Microsoft Exchange Server that allows for spoofing.
2
How severe is CVE-2022-24463?
CVE-2022-24463 has a severity rating of 6.5 (high).
3
Which versions of Microsoft Exchange Server are affected by CVE-2022-24463?
CVE-2022-24463 affects Microsoft Exchange Server 2016 cumulative update 21 and 22, as well as Microsoft Exchange Server 2019 cumulative update 10 and 11.
4
How do I fix CVE-2022-24463?
To fix CVE-2022-24463, apply the appropriate cumulative update for your version of Microsoft Exchange Server. Microsoft has provided patches and remediation steps, which can be found in their official documentation.
5
Where can I find more information about CVE-2022-24463?
You can find more information about CVE-2022-24463 on the Microsoft Security Response Center website.