3 Microsoft Exchange EOPs (CVE-2022-21980, CVE-2022-24516, CVE-2022-24477)

Опубликовано: 07 Июнь 2026
на канале: Alexander Leonov
95
1

Elevation of Privilege in #Microsoft #Exchange (CVE-2022-21980, CVE-2022-24516, CVE-2022-24477). I will not hide, this vulnerabilities were not detected as critical by Vulristics, only as Medium. This happened due to the fact that this are not RCEs, but EOPs. No public exploit or sign of exploitation in the wild. But these vulnerabilities are very critical, due to the fact that Exchange is often accessible from the Internet. And because of details about the vulnerability, which is only highlighted by ZDI. These bugs could allow an authenticated attacker to take over the mailboxes of all Exchange users, read and send emails or download attachments from any mailbox on the Exchange server. This gives access to valuable data and great opportunities for developing an attack. Administrators will also need to enable Extended Protection to fully address these vulnerabilities.

it is not clear how to highlight such vulnerabilities automatically, because there are few formal signs. Apparently it is required to raise the priority of the software available on the perimeter and software that operates with important data.

Telegram: https://t.me/avleonovcom/1031
Blogpost: https://avleonov.com/2022/08/23/micro...