CVE-2022-41080
Microsoft Exchange Server Privilege Escalation Vulnerability
CVSS
8.8
High
EPSS
77.3%
p100
KEV
YES
Jan 10, 2023
Exploit Today
80
0-100
Published: Nov 9, 2022 · Last modified: Aug 10, 2026
Product
Microsoft / Exchange Server
Vulnerability
Microsoft Exchange Server Privilege Escalation Vulnerability
Added to KEV
Jan 10, 2023
Remediate by
Jan 31, 2023
Known ransomware use
Yes
Summary description
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.
Required action
Apply updates per vendor instructions.
Notes
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41080; https://nvd.nist.gov/vuln/detail/CVE-2022-41080
Microsoft Exchange Server Elevation of Privilege Vulnerability