CVE-2022-21846 PUBLISHED CVSS 9 CRITICAL

Microsoft Exchange Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-21855, CVE-2022-21969.

EPSS 1.53% · 81.2th percentile

Risk Scores

CVSS v3.1
9
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
1.53%
81.2th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 2215.0.0
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 1015.02.0
MicrosoftMicrosoft Exchange Server 2013 Cumulative Update 2315.00.0
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 2115.01.0
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 1115.02.0
microsoftexchange_server15.02.0, 2013, 2016

Timeline

References

Open in Interactive Console →