Permissions, Privileges, and Access Controls in Microsoft Exchange Server - CVE-2022-21980
Published: August 9, 2022
Vulnerability identifier: #VU66292
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21980
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions. A remote attacker can trick the victim into visiting a specially crafted server share or website and gain elevated privileges.
Affected software
Microsoft Exchange Server
How to mitigate CVE-2022-21980
Install updates from vendor's website.
Microsoft Exchange Server - addressed in versions 2013 Cumulative Update 23 Aug22SU 15.00.1497.040, 2016 Cumulative Update 22 Aug22SU 15.01.2375.031, 2016 Cumulative Update 23 Aug22SU 15.01.2507.012, 2019 Cumulative Update 11 Aug22SU 15.02.0986.029, 2019 Cumulative Update 12 Aug22SU 15.02.1118.012