GSD-2022-1006325

Source
https://data.gsd.id/GSD-2022-1006325
Import Source
https://github.com/cloudsecurityalliance/gsd-database/blob/main/2022/1006xxx/GSD-2022-1006325.json
JSON Data
https://api.osv.dev/v1/vulns/GSD-2022-1006325
Withdrawn
2023-03-14T07:01:09Z
Published
2022-09-29T23:23:51Z
Modified
2023-03-14T07:01:09Z
Summary
unknown in Exchange Server version Exchange Server 2019
Details

In Microsoft Exchange Server version Exchange Server 2019 and possibly earlier an undisclosed vulnerability exists in an undisclosed component that can be attacked via the network, reportedly resulting in remote code execution. This is also known as ZDI-CAN-18333, and public reports of exploitation are available. There are additional reports that indicate that attackers may be making use of an older, known (and fixed) vulnerability and that these newly exploited systems are not correctly patched and vulnerable to older exploits, however it should be noted that the ZDI reference does exist.

References

Affected packages

GSD / Exchange Server

Package

Name
Exchange Server

Affected ranges

Affected versions

Other
Exchange Server 2019

Database specific

source
"https://github.com/cloudsecurityalliance/gsd-database/blob/main/2022/1006xxx/GSD-2022-1006325.json"