Improper access control in Microsoft Exchange Server - CVE-2022-21979
Published: August 9, 2022
Vulnerability identifier: #VU66288
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21979
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can bypass implemented security restrictions and read targeted email messages.
Affected software
Microsoft Exchange Server
How to mitigate CVE-2022-21979
Install updates from vendor's website.
Microsoft Exchange Server - addressed in versions 2013 Cumulative Update 23 Aug22SU 15.00.1497.040, 2016 Cumulative Update 22 Aug22SU 15.01.2375.031, 2016 Cumulative Update 23 Aug22SU 15.01.2507.012, 2019 Cumulative Update 11 Aug22SU 15.02.0986.029, 2019 Cumulative Update 12 Aug22SU 15.02.1118.012