CVE-2022-21978

Description

Microsoft Exchange Server Elevation of Privilege Vulnerability

Risk Information

Base Score
7.7
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.524

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Exchange Server Elevation of Privilege Vulnerability For Exchange Server 2013 CU23 (KB5014260)Windows
Microsoft Exchange Server Elevation of Privilege Vulnerability For Exchange Server 2016 CU22 (KB5014261)Windows
Microsoft Exchange Server Elevation of Privilege Vulnerability For Exchange Server 2016 CU23 (KB5014261)Windows
Microsoft Exchange Server Elevation of Privilege Vulnerability For Exchange Server 2019 CU11 (KB5014261)Windows
Microsoft Exchange Server Elevation of Privilege Vulnerability For Exchange Server 2019 CU12 (KB5014261)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-33738Security Update For Exchange Server 2013 CU23 (KB5014260)
PATCH-33739Security Update For Exchange Server 2016 CU22 (KB5014261)
PATCH-33740Security Update For Exchange Server 2016 CU23 (KB5014261)
PATCH-33741Security Update For Exchange Server 2019 CU11 (KB5014261)
PATCH-33742Security Update For Exchange Server 2019 CU12 (KB5014261)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234