CVE-2022-38784

Vulnerability updated 5 months ago (2024-05-04T17:58:48.312Z)
Download STIX
Preview STIX
CVE-2022-38784 is a vulnerability that affects the Microsoft Exchange Server. The vulnerability was discovered in June 2022 and was assigned a critical severity rating of 9.8 out of 10. It occurs due to an improper validation of user-supplied data in the ECP module of the Exchange Server, which allows remote attackers to execute arbitrary code with SYSTEM privileges on the target system. This vulnerability was actively exploited by threat actors within days of its disclosure. The exploitation attempts were primarily targeting organizations in the United States and Europe. The attacks involved the deployment of a web shell onto the compromised servers, giving attackers complete control over the victim's system. According to Microsoft, the attacks were likely carried out by a Chinese state-sponsored hacking group known as Hafnium. In response to this vulnerability, Microsoft released emergency patches for all affected versions of Exchange Server. Organizations were advised to apply the updates immediately to prevent exploitation. Additionally, Microsoft recommended that organizations review their network perimeter defenses and implement multi-factor authentication and least privilege access controls to reduce the risk of future attacks.
Description last updated: 2023-06-23T17:19:27.089Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2022-38784 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
2 years ago
CERT-EU
a year ago