Junglewise Threat Intelligence

CVE-2022-41080: Microsoft Exchange Server Privilege Escalation Vulnerability

CVE-2022-41080 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-01-10

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server contains an elevation of privilege vulnerability that allows an attacker to escalate permissions. This flaw is known to be chainable with CVE-2022-41082 to achieve remote code execution and has been observed being exploited in the wild.

Affected products

  • Microsoft Exchange Server 2013 Cumulative Update 23, 2016 Cumulative Update 22, 2016 Cumulative Update 23, 2019 Cumulative Update 11, 2019 Cumulative Update 12

Timeline

  • 2022-11-09: disclosed: NVD Published Date
  • 2023-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-01-10: advisory: Published date listed in advisory summary

Related threats