Executive brief
Microsoft Exchange Server contains an information disclosure vulnerability that allows an unauthenticated attacker to intercept email traffic. The flaw stems from insufficient information handling, potentially leading to the exposure of sensitive communication.
Affected products
- Microsoft Exchange Server 2013 Cumulative Update 23
- Microsoft Exchange Server 2016 Cumulative Update 19, Cumulative Update 20
- Microsoft Exchange Server 2019 Cumulative Update 8, Cumulative Update 9
Timeline
- 2021-07-14: disclosed: NVD Published Date
- 2022-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-01-18: exploited: Confirmed exploited in the wild per CISA KEV entry