Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution. Required action: Apply updates per vendor instructions.
Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution. Required action: Apply updates per vendor instructions.
Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution. Required action: Apply updates per vendor instructions.
A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server. Required action: Apply updates per vendor instructions.
Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target. Required action: Apply updates per vendor instructions.
Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution. Required action: Apply updates per vendor instructions.
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. Required action: Apply updates per vendor instructions.
Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution. Required action: Apply updates per vendor instructions.
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. Required action: Apply updates per vendor instructions.
Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass. Required action: Apply updates per vendor instructions.
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. Required action: Apply updates per vendor instructions.
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. Required action: Apply updates per vendor instructions.
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. Required action: Apply updates per vendor instructions.
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. Required action: Apply updates per vendor instructions.