Input validation error in Microsoft Exchange Server - CVE-2022-21969

 

Input validation error in Microsoft Exchange Server - CVE-2022-21969

Published: January 11, 2022


Vulnerability identifier: #VU59410
CSH Severity: Medium
CVSS v4: 9.4 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2022-21969
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote user on the local network can send specially crafted data to the Exchange server and execute arbitrary code on the system.

Affected software

Microsoft Exchange Server

How to mitigate CVE-2022-21969

Install updates from vendor's website.


External References

Related Security Bulletins