CVE-2022-23277
HIGHMicrosoft Exchange Server ChainedSerializationBinder RCE
Title source: metasploitDescription
Microsoft Exchange Server Remote Code Execution Vulnerability
Exploits (2)
metasploit
WORKING POC
EXCELLENT
by pwnforsp, zcgonvh, Microsoft Threat Intelligence Center, Microsoft Security Response Center, peterjson, testanull, Grant Willcox, Spencer McIntyre, Markus Wulftange · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/exchange_chainedserializationbinder_rce.rb
Scores
CVSS v3
8.8
EPSS
0.7912
EPSS Percentile
99.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (3)
microsoft/exchange_server
2013 cumulative_update_23
microsoft/exchange_server
2016 cumulative_update_21 (2 CPE variants)
microsoft/exchange_server
2019 cumulative_update_10 (2 CPE variants)
Published
Mar 09, 2022
Tracked Since
Feb 18, 2026