CVE-2022-21979
published 2022-08-09CVE-2022-21979: Microsoft Exchange Server Information Disclosure Vulnerability
PriorityP428medium5.7CVSS 3.1
AVNACLPRLUIRSUCHINAN
EPSS
1.85%
76.7th percentile
Microsoft Exchange Server Information Disclosure Vulnerability
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | microsoft_exchange_server_2013_cumulative_update_23 | >= 15.00.0 < 15.00.1497.042 | 15.00.1497.042 |
| microsoft | microsoft_exchange_server_2016_cumulative_update_22 | >= 15.0.0 < 15.01.2375.032 | 15.01.2375.032 |
| microsoft | microsoft_exchange_server_2016_cumulative_update_23 | >= 15.01.0 < 15.01.2507.013 | 15.01.2507.013 |
| microsoft | microsoft_exchange_server_2019_cumulative_update_11 | >= 15.02.0 < 15.02.0986.030 | 15.02.0986.030 |
| microsoft | microsoft_exchange_server_2019_cumulative_update_12 | >= 15.02.0 < 15.02.1118.015 | 15.02.1118.015 |
| msrc | microsoft_exchange_server_2013_cumulative_update_23 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_22 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_23 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_11 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_12 | — | — |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
vendor_msrc4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fvf6-pmf5-8mmf: Microsoft Exchange Information Disclosure Vulnerability
ghsa_unreviewed·2022-08-10·CVSS 6.5
CVE-2022-21979 [MEDIUM] GHSA-fvf6-pmf5-8mmf: Microsoft Exchange Information Disclosure Vulnerability
Microsoft Exchange Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-30134, CVE-2022-34692.
GHSA
GHSA-fv6h-3g6p-m8px: Microsoft Exchange Information Disclosure Vulnerability
ghsa_unreviewed·2022-08-10·CVSS 4.8
CVE-2022-30134 [MEDIUM] GHSA-fv6h-3g6p-m8px: Microsoft Exchange Information Disclosure Vulnerability
Microsoft Exchange Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-21979, CVE-2022-34692.
GHSA
GHSA-9qvw-444r-5wp7: Microsoft Exchange Information Disclosure Vulnerability
ghsa_unreviewed·2022-08-10·CVSS 4.8
CVE-2022-34692 [MEDIUM] CWE-200 GHSA-9qvw-444r-5wp7: Microsoft Exchange Information Disclosure Vulnerability
Microsoft Exchange Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-21979, CVE-2022-30134.
Microsoft
Microsoft Exchange Server Information Disclosure Vulnerability
vendor_msrc·2022-08-09·CVSS 4.8
CVE-2022-21979 [MEDIUM] Microsoft Exchange Server Information Disclosure Vulnerability
Microsoft Exchange Server Information Disclosure Vulnerability
FAQ: Are there any more actions I need to take to be protected from this vulnerability?
Yes. Customers running an affected version of Microsoft Exchange need to enable Extended Protection to be protected from this vulnerability. For more information, see Exchange Server Support for Windows Extended Protection.
Is there more information available about this release of Exchange Server?
For more information on this issue, please see The Exchange Blog.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited the vulnerability could read targeted email messages.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-09
Published