Executive brief
Microsoft Exchange Server contains an elevation of privilege vulnerability that allows an attacker to escalate permissions. This flaw is known to be chainable with CVE-2022-41082 to achieve remote code execution and has been observed being exploited in the wild.
Affected products
- Microsoft Exchange Server 2013 Cumulative Update 23, 2016 Cumulative Update 22, 2016 Cumulative Update 23, 2019 Cumulative Update 11, 2019 Cumulative Update 12
Timeline
- 2022-11-09: disclosed: NVD Published Date
- 2023-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-01-10: advisory: Published date listed in advisory summary