Описание
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 15.02.2562.045 (исключая)
Одно из
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_subscription_edition:*:*:*:*:*:*:*:*
EPSS
Процентиль: 12%
0.00219
Низкий
7.8 High
CVSS3
Дефекты
CWE-1220
Связанные уязвимости
CVSS3: 7.8
msrc
20 дней назад
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVSS3: 7.8
github
19 дней назад
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
EPSS
Процентиль: 12%
0.00219
Низкий
7.8 High
CVSS3
Дефекты
CWE-1220