|CERT-In Vulnerability Note
Multiple Vulnerabilities in Microsoft Exchange Server
Original Issue Date:September 30, 2022
Severity Rating: HIGH
- Microsoft Exchange Server versions 2013, 2016, and 2019.
Multiple vulnerabilities have been reported in Microsoft Exchange Server, which could allow an attacker to perform remote code execution on the targeted system.
These vulnerabilities exist in Microsoft Exchange Server due to post-authentication flaws. An authenticated attacker could exploit these vulnerabilities by sending a specially-crafted request to the affected system.
Successful exploitation of these vulnerabilities could allow an attacker to perform remote code execution on the targeted system.
Note: These vulnerabilities are being exploited in the wild.
A patch for the vulnerabilities is currently not available. As a workaround, apply appropriate mitigations issued by the vendor:
The information provided herein is on "as is" basis, without warranty of any kind.
Email: firstname.lastname@example.org Phone: +91-11-24368572
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
6, CGO Complex, Lodhi Road,
New Delhi - 110 003