⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply updates per vendor instructions.. Due date: 2023-01-31.
CVE-2022-41080 — Microsoft Exchange Server 2013 Cumulative Update 23 vulnerability
12 documents9 sources
Severity
9.8CRITICALNVD
CNA8.8VulnCheck8.8
EPSS
93.8%
top 0.14%
CISA KEV
KEVRansomware
Added 2023-01-10
Due 2023-01-31
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedNov 9
KEV addedJan 10
KEV dueJan 31
CISA Required Action: Apply updates per vendor instructions.
Description
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages6 packages
Patches
🔴Vulnerability Details
3📋Vendor Advisories
2🕵️Threat Intelligence
6Huntress
▶