QID 50118

Date Published: 2022-01-12

QID 50118: Microsoft Exchange Server Remote Code Execution (RCE) Vulnerability for January 2022

Microsoft Exchange Server Remote Code Execution Vulnerability

KB Articles associated with this update are: KB5008631

Affected Versions:
Microsoft Exchange Server 2019 Cumulative Update 11
Microsoft Exchange Server 2016 Cumulative Update 22
Microsoft Exchange Server 2019 Cumulative Update 10
Microsoft Exchange Server 2016 Cumulative Update 21
Microsoft Exchange Server 2013 Cumulative Update 23

QID Detection Logic (authenticated):
The QID checks for the version of file Exsetup.exe.

Successful exploitation allows attackers to execute remote code.

  • CVSS V3 rated as Critical - 9 severity.
  • CVSS V2 rated as Critical - 8.3 severity.
  • Solution
    Customers are advised to refer to KB5008631 for information pertaining to this vulnerability.

    CVEs related to QID 50118

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-21846 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21846
    CVE-2022-21855 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21855
    CVE-2022-21969 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21969