MS.Exchange.EWS.UserConfiguration.Insecure.Deserialization

description-logoDescription

This indicates an attack attempt to exploit an Insecure Deserialization Vulnerability in Microsoft Exchange Server.
The vulnerability is due to improper handling of EWS requests containing malicious UserConfiguration objects. This vulnerability is due to an incomplete fix of CVE-2021-42321. A remote, authenticated attacker can exploit this vulnerability by sending crafted traffic to the target system. Successful exploitation could result in remote code execution in the security context of the SYSTEM user.

affected-products-logoAffected Products

Microsoft Exchange Server 2013 Cumulative Update 23
Microsoft Exchange Server 2016 Cumulative Update 21
Microsoft Exchange Server 2016 Cumulative Update 22
Microsoft Exchange Server 2019 Cumulative Update 10
Microsoft Exchange Server 2019 Cumulative Update 11

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23277

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2022-08-02 21.366 Default_action:pass:drop
2022-07-21 21.361