CVE-2022-29901

Vulnerability updated 4 months ago (2024-05-04T17:50:55.374Z)
Download STIX
Preview STIX
CVE-2022-29901 is a vulnerability found in the Microsoft Exchange Server that could allow an attacker to execute arbitrary code with SYSTEM privileges. This vulnerability is caused by improper validation of user-supplied input within the web management interface of the Microsoft Exchange Server. The exploitation of this flaw could enable attackers to gain access to sensitive information, install malware, modify data, and create new accounts with full user rights. The vulnerability was discovered on April 12, 2022, by researchers from the Qihoo 360 Vulcan team. Microsoft released security updates to address this vulnerability on May 10, 2022, as part of its monthly patch update. It is highly recommended that all users of the affected software apply these patches as soon as possible to prevent exploitation of the vulnerability. This vulnerability has been rated as critical by both Microsoft and the National Vulnerability Database (NVD) due to the potential for attackers to gain full control of the vulnerable system. Organizations should take immediate action to ensure their systems are protected against this vulnerability by installing the necessary security updates provided by Microsoft.
Description last updated: 2023-06-13T16:13:05.301Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2022-29901 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
2 years ago
Ubuntu update for linux-hwe
CERT-EU
2 years ago
Ubuntu 5883-1: Linux kernel (HWE) vulnerabilities | LinuxSecurity.com