CVE-2022-24463HighCVSS 6.5

Microsoft Exchange Server Spoofing Vulnerability

Published
March 8, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, privileges required is low (PR:L). Does the attacker need to be in an authenticated role on the Exchange Server? Yes, the attacker must be authenticated.

What is the nature of the spoofing? An authenticated attacker could make a specially crafted network call to the target Exchange Server that causes the parsing of an http request made to an attacker-controlled server. This could lead to the disclosure of files from the target Exchange Server.

What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is file content.

🎯 Affected products4

  • Microsoft Exchange Server 2016 Cumulative Update 21
  • Microsoft Exchange Server 2016 Cumulative Update 22
  • Microsoft Exchange Server 2019 Cumulative Update 10
  • Microsoft Exchange Server 2019 Cumulative Update 11

✅ Remediation

KB5012698 (Security Update) — fixed build 15.01.2308.027 KB5012698 (Security Update) — fixed build 15.02.0922.027 KB5012698 (Security Update) — fixed build 15.01.2375.024 KB5012698 (Security Update) — fixed build 15.02.0986.022

🔗 References (6)