Information disclosure in Microsoft Exchange Server - CVE-2022-34692

 

Information disclosure in Microsoft Exchange Server - CVE-2022-34692

Published: August 9, 2022


Vulnerability identifier: #VU66325
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-34692
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application in the Microsoft Exchange. A remote attacker can read targeted email messages.


Affected software

Microsoft Exchange Server

How to mitigate CVE-2022-34692

Install updates from vendor's website.

Microsoft Exchange Server - addressed in versions 2016 Cumulative Update 22 Aug22SU 15.01.2375.031, 2016 Cumulative Update 23 Aug22SU 15.01.2507.012, 2019 Cumulative Update 11 Aug22SU 15.02.0986.029, 2019 Cumulative Update 12 Aug22SU 15.02.1118.012

External References

Related Security Bulletins