'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-05-06 | |
| Rule Name: | Microsoft Exchange Server Remote Code Execution Vulnerability (CVE-2022-23277) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | Microsoft Exchange Server is an email service program developed by Microsoft Corporation of the United States. It provides functions including email access, storage, forwarding, voicemail, and mail filtering. Microsoft Exchange Server has code injection vulnerabilities. | |
| Impact: | Successful exploitation allows an attacker to execute arbitrary code with SYSTEM privileges on the Exchange server, leading to complete system compromise, unauthorized access to email data, and potential lateral movement to other systems in the network. | |
| Affected OS: | Windows | |
| Reference: | CVE-2022-23277 |
|
| Solutions |
|---|
| Please refer to announcements or patches release by the vendor: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23277 |