CVE-2022-41080: Microsoft Exchange Server Privilege Escalation Vulnerability
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.
Other sources
Microsoft Exchange Server Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.0986.036Patch KB5019758 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2375.037Patch KB5019758 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.016Patch KB5019758 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.00.1497.044Patch KB5019758 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1118.020Patch KB5019758
Event History
Frequently Asked Questions
What is CVE-2022-41080?
CVE-2022-41080 is a privilege escalation vulnerability in Microsoft Exchange Server.
How does CVE-2022-41080 affect Microsoft Exchange Server?
CVE-2022-41080 allows an attacker to escalate privileges on a Microsoft Exchange Server.
Is CVE-2022-41080 chained with another vulnerability?
Yes, CVE-2022-41080 is chainable with CVE-2022-41082, which allows for remote code execution.
What is the severity level of CVE-2022-41080?
The severity level of CVE-2022-41080 is not specified in the vulnerability report.
How can I protect my Microsoft Exchange Server from CVE-2022-41080?
To protect your Microsoft Exchange Server from CVE-2022-41080, apply the necessary security patches provided by Microsoft.