CVE-2022-21855 PUBLISHED CVSS 9 CRITICAL

Microsoft Exchange Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-21846, CVE-2022-21969.

EPSS 1.53% · 81.2th percentile

Risk Scores

CVSS v3.1
9
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
1.53%
81.2th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 2215.0.0
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 1115.02.0
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 2115.01.0
microsoftexchange_server2019, 2016, 2019
MicrosoftMicrosoft Exchange Server 2013 Cumulative Update 2315.00.0
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 1015.02.0

Timeline

References

Open in Interactive Console →