CVE-2022-21978
published 2022-05-10CVE-2022-21978: Microsoft Exchange Server Elevation of Privilege Vulnerability
PriorityP337high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
EPSS
0.84%
53.8th percentile
Microsoft Exchange Server Elevation of Privilege Vulnerability
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | microsoft_exchange_server_2013_cumulative_update_23 | >= 15.00.0 < 15.00.1497.36 | 15.00.1497.36 |
| microsoft | microsoft_exchange_server_2016_cumulative_update_22 | >= 15.0.0 < 15.01.2375.028 | 15.01.2375.028 |
| microsoft | microsoft_exchange_server_2016_cumulative_update_23 | >= 15.01.0 < 15.01.2507.009 | 15.01.2507.009 |
| microsoft | microsoft_exchange_server_2019_cumulative_update_11 | >= 15.02.0 < 15.02.0986.026 | 15.02.0986.026 |
| microsoft | microsoft_exchange_server_2019_cumulative_update_12 | >= 15.02.0 < 15.02.1118.009 | 15.02.1118.009 |
| msrc | microsoft_exchange_server_2013_cumulative_update_23 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_22 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_23 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_11 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_12 | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-72rg-xpq2-2j8c: Microsoft Exchange Server Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-11
CVE-2022-21978 [HIGH] GHSA-72rg-xpq2-2j8c: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability.
Microsoft
Microsoft Exchange Server Elevation of Privilege Vulnerability
vendor_msrc·2022-05-10·CVSS 8.2
CVE-2022-21978 [HIGH] Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
FAQ: Do I need to take further steps to be protected from this vulnerability?
Because of additional security hardening work for CVE-2022-21978, the following actions should be taken in addition to application of May 2022 security updates:
For customers that have Exchange Server 2016 CU22 or CU23, or Exchange Server 2019 CU11 or CU12 installed
Install the May 2022 SU first and then run one of the following commands using Setup.exe in your Exchange Server installation path (e.g., …\Program Files\Microsoft\Exchange Server\v15\Bin):
Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataON /PrepareAllDomains
Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataOFF /PrepareAllDomains
For customers that have Exchange S
No detection rules found.
No public exploits indexed.
Tenable
Microsoft’s May 2022 Patch Tuesday Addresses 73 CVEs (CVE-2022-26925)
blogs_tenable·2022-05-10·CVSS 8.1
[HIGH] Microsoft’s May 2022 Patch Tuesday Addresses 73 CVEs (CVE-2022-26925)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical.
blogs_qualys·2022-05-10·CVSS 5.6
[MEDIUM] May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
Notable Microsoft Vulnerabilities Patched
Microsoft Last But Not Least
Notable Adobe Vulnerabilities Patched
About Qualys Patch Tuesday
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response with Patch Management (PM)
Qualys Monthly Webinar Series
Join the webinar this Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 75 vulnerabilities in the May 2022 update, including one advisory ( ADV220001 ) for Azure in response to CVE-2022-29972 , a publicly exposed Zero-Day Remote Code Execution (RCE) Vulnerability, and eight vulnerabilities classified as critical as they allow Remote Code Execution (RCE) or Elevation of Privileges. This month
Qualys
May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical. | Qualys
blogs_qualys·2022-05-10·CVSS 5.6
[MEDIUM] May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- Notable Microsoft Vulnerabilities Patched
- Microsoft Last But Not Least
- Notable Adobe Vulnerabilities Patched
- About Qualys Patch Tuesday
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response with Patch Management (PM)
- Qualys Monthly Webinar Series
- Join the webinar this Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 75 vulnerabilities in the May 2022 update, including one advisory ( ADV220001 ) for Azure in response to CVE-2022-29972, a publicly exposed Zero-Day Remote Code Execution (RCE) Vulnerability, and eight vulnerabilities classified as critical as they allow Remote Code Execution (RCE) or Elevation of Privileges.
Crowdstrike
May 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] May 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2022-05-10
Published