cbcvebase.
CVE-2022-24463
published 2022-03-09

CVE-2022-24463: Microsoft Exchange Server Spoofing Vulnerability Microsoft Exchange Server Spoofing Vulnerability

medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
31.79%
98.1th percentile
Microsoft Exchange Server Spoofing Vulnerability Microsoft Exchange Server Spoofing Vulnerability

Affected

8 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_exchange_server_2016_cumulative_update_21>= 15.01.0 < 15.01.2308.02715.01.2308.027
microsoftmicrosoft_exchange_server_2016_cumulative_update_22>= 15.0.0 < 15.01.2375.02415.01.2375.024
microsoftmicrosoft_exchange_server_2019_cumulative_update_10>= 15.02.0 < 15.02.0922.02715.02.0922.027
microsoftmicrosoft_exchange_server_2019_cumulative_update_11>= 15.02.0 < 15.02.0986.02215.02.0986.022
msrcmicrosoft_exchange_server_2016_cumulative_update_21
msrcmicrosoft_exchange_server_2016_cumulative_update_22
msrcmicrosoft_exchange_server_2019_cumulative_update_10
msrcmicrosoft_exchange_server_2019_cumulative_update_11

Detection & IOCsextracted from sources · hover to see the quote

  • Attacker sends a specially crafted network call to the target Exchange Server that causes parsing of an HTTP request made to an attacker-controlled server — monitor Exchange Server outbound HTTP requests to unexpected/external destinations as a sign of exploitation.
  • Exploitation results in disclosure of file content from the Exchange Server — monitor for unexpected file reads or access to sensitive Exchange files following inbound authenticated network calls.
  • Requires low-privilege authenticated access to Exchange Server — correlate with authenticated (low-privilege) user activity on Exchange Server preceding any anomalous outbound HTTP connections.
  • ·Exploitation is assessed as 'Less Likely' for both latest and older software releases as of the advisory publication date; no public exploits or in-the-wild exploitation confirmed.

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
cvelistv56.5MEDIUM
vulncheck6.5MEDIUM
vendor_msrc6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.