Permissions, Privileges, and Access Controls in Microsoft Exchange Server - CVE-2022-21980

 

Permissions, Privileges, and Access Controls in Microsoft Exchange Server - CVE-2022-21980

Published: August 9, 2022


Vulnerability identifier: #VU66292
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21980
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions. A remote attacker can trick the victim into visiting a specially crafted server share or website and gain elevated privileges.


Affected software

Microsoft Exchange Server

How to mitigate CVE-2022-21980

Install updates from vendor's website.

Microsoft Exchange Server - addressed in versions 2013 Cumulative Update 23 Aug22SU 15.00.1497.040, 2016 Cumulative Update 22 Aug22SU 15.01.2375.031, 2016 Cumulative Update 23 Aug22SU 15.01.2507.012, 2019 Cumulative Update 11 Aug22SU 15.02.0986.029, 2019 Cumulative Update 12 Aug22SU 15.02.1118.012

External References

Related Security Bulletins