cbcvebase.
CVE-2022-23277
published 2022-03-09

CVE-2022-23277: Microsoft Exchange Server Remote Code Execution Vulnerability

PriorityP274high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
40.79%
98.5th percentile
Microsoft Exchange Server Remote Code Execution Vulnerability

Affected

13 ranges
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server_2013_cumulative_update_23>= 15.00.0 < 15.00.1497.03315.00.1497.033
microsoftmicrosoft_exchange_server_2016_cumulative_update_21>= 15.01.0 < 15.01.2308.02715.01.2308.027
microsoftmicrosoft_exchange_server_2016_cumulative_update_22>= 15.0.0 < 15.01.2375.02415.01.2375.024
microsoftmicrosoft_exchange_server_2019_cumulative_update_10>= 15.02.0 < 15.02.0922.02715.02.0922.027
microsoftmicrosoft_exchange_server_2019_cumulative_update_11>= 15.02.0 < 15.02.0986.02215.02.0986.022
msrcmicrosoft_exchange_server_2013_cumulative_update_23
msrcmicrosoft_exchange_server_2016_cumulative_update_21
msrcmicrosoft_exchange_server_2016_cumulative_update_22
msrcmicrosoft_exchange_server_2019_cumulative_update_10
msrcmicrosoft_exchange_server_2019_cumulative_update_11

Detection & IOCsextracted from sources · hover to see the quote

snort
59210 - 59217, 59220 and 59221
  • Exploitation requires an authenticated network call targeting Exchange Server accounts; monitor for authenticated Exchange Web Services (EWS) or HTTP requests that attempt to trigger code execution in the server account context.
  • The Metasploit module targets the ChainedSerializationBinder attack surface in Exchange Server 2019 CU10/CU11 and Exchange Server 2016 CU21/CU22 prior to Mar22SU; look for exploitation attempts against these specific CU versions.
  • ·Exploitation requires low-privilege authentication on the Exchange Server; unauthenticated exploitation is not possible for this CVE.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.