Microsoft Exchange Server Elevation of Privilege Vulnerability
Published: 2022-09-30
Microsoft has confirmed reports of two zero-day vulnerabilities in Microsoft Exchange Server that have been exploited in the wild. Patches are not yet available.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a
https://www.tenable.com/blog/microsofts-feb-2024-patch-tuesday-cve-2024-21351-cve-2024-21412
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-352a
https://www.mandiant.com/resources/blog/zero-days-exploited-2022
https://www.tenable.com/cyber-exposure/tenable-2022-threat-landscape-report
https://www.tenable.com/blog/microsofts-october-2022-patch-tuesday-addresses-84-cves-cve-2022-41033
https://www.kb.cert.org/vuls/id/915563
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41040