Lucene search

K
kasperskyKaspersky LabKLA12608
HistoryAug 09, 2022 - 12:00 a.m.

KLA12608 Multiple vulnerabilities in Microsoft Exchange Server

2022-08-0900:00:00
Kaspersky Lab
threats.kaspersky.com
40
microsoft
exchange server
vulnerabilities
remote
information disclosure
privilege escalation
sensitive information
gain privileges
cve
kb
updates
impacted products

CVSS3

8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

High

EPSS

0.017

Percentile

88.0%

Multiple vulnerabilities were found in Microsoft Exchange Server. Malicious users can exploit these vulnerabilities to obtain sensitive information, gain privileges.

Below is a complete list of vulnerabilities:

  1. An information disclosure vulnerability in Microsoft Exchange can be exploited remotely to obtain sensitive information.
  2. An elevation of privilege vulnerability in Microsoft Exchange Server can be exploited remotely to gain privileges.

Original advisories

CVE-2022-30134

CVE-2022-24516

CVE-2022-21979

CVE-2022-34692

CVE-2022-21980

CVE-2022-24477

Related products

Microsoft-Exchange-Server

CVE list

CVE-2022-30134 high

CVE-2022-24516 critical

CVE-2022-21979 warning

CVE-2022-34692 high

CVE-2022-21980 critical

CVE-2022-24477 critical

KB list

5015322

5019076

5019077

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

Affected Products

  • Microsoft Exchange Server 2019 Cumulative Update 11Microsoft Exchange Server 2013 Cumulative Update 23Microsoft Exchange Server 2016 Cumulative Update 22Microsoft Exchange Server 2019 Cumulative Update 12Microsoft Exchange Server 2016 Cumulative Update 23

CVSS3

8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

High

EPSS

0.017

Percentile

88.0%