First published: Tue Nov 08 2022(Updated: )
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2013-cumulative_update_23 | |
Microsoft Exchange Server | =2016-cumulative_update_22 | |
Microsoft Exchange Server | =2016-cumulative_update_23 | |
Microsoft Exchange Server | =2019-cumulative_update_11 | |
Microsoft Exchange Server | =2019-cumulative_update_12 | |
Microsoft Exchange Server 2019 | =11 | |
Microsoft Exchange Server 2016 | =23 | |
Microsoft Exchange Server 2016 | =22 | |
Microsoft Exchange Server 2019 | =12 | |
Microsoft Exchange Server 2013 | =23 | |
Microsoft Exchange Server | ||
=2013-cumulative_update_23 | ||
=2016-cumulative_update_22 | ||
=2016-cumulative_update_23 | ||
=2019-cumulative_update_11 | ||
=2019-cumulative_update_12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41080 is a privilege escalation vulnerability in Microsoft Exchange Server.
CVE-2022-41080 allows an attacker to escalate privileges on a Microsoft Exchange Server.
Yes, CVE-2022-41080 is chainable with CVE-2022-41082, which allows for remote code execution.
The severity level of CVE-2022-41080 is not specified in the vulnerability report.
To protect your Microsoft Exchange Server from CVE-2022-41080, apply the necessary security patches provided by Microsoft.