PT-2022-34582 · Microsoft · Exchange Server

Published

2022-09-29

·

Updated

2022-09-29

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server version Exchange Server 2019 and possibly earlier
Description An undisclosed vulnerability exists in an undisclosed component of Microsoft Exchange Server, allowing for remote code execution via network attack. Public reports of exploitation are available, and it is also referred to as ZDI-CAN-18333. Additionally, there are reports that attackers may be exploiting an older, known vulnerability in systems that are not correctly patched.
Recommendations For Microsoft Exchange Server version Exchange Server 2019 and possibly earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

GSD-2022-1006325

Affected Products

Exchange Server