Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Microsoft Exchange Server 2013 Cumulative Update 23 | 15.00.0 ~ 15.00.1497.033 | - | |
| Microsoft | Microsoft Exchange Server 2016 Cumulative Update 21 | 15.01.0 ~ 15.01.2308.027 | - | |
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 10 | 15.02.0 ~ 15.02.0922.027 | - | |
| Microsoft | Microsoft Exchange Server 2016 Cumulative Update 22 | 15.0.0 ~ 15.01.2375.024 | - | |
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 11 | 15.02.0 ~ 15.02.0986.022 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2022-23277 POC to write a webshell to aspnet_client | https://github.com/7BitsTeam/CVE-2022-23277 | POC Details |
| 2 | 将常用的cve工具做个备份(CVE-2021-42321,CVE-2022-23277,CVE-2022-41082,Exchange_GetVersion_MatchVul) | https://github.com/gmeier909/exchange_tools | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-23294 | 8.8 HIGH | Windows Event Tracing Remote Code Execution Vulnerability |
| CVE-2022-23285 | 8.8 HIGH | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2022-21990 | 8.8 HIGH | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2022-24508 | 8.8 HIGH | Win32 File Enumeration Remote Code Execution Vulnerability |
| CVE-2022-24469 | 8.1 HIGH | Azure Site Recovery Elevation of Privilege Vulnerability |
| CVE-2022-24455 | 7.8 HIGH | Windows CD-ROM Driver Elevation of Privilege Vulnerability |
| CVE-2022-24459 | 7.8 HIGH | Windows Fax and Scan Service Elevation of Privilege Vulnerability |
| CVE-2022-24461 | 7.8 HIGH | Microsoft Office Visio Remote Code Execution Vulnerability |
| CVE-2022-24501 | 7.8 HIGH | VP9 Video Extensions Remote Code Execution Vulnerability |
| CVE-2022-24510 | 7.8 HIGH | Microsoft Office Visio Remote Code Execution Vulnerability |
| CVE-2022-24457 | 7.8 HIGH | HEIF Image Extensions Remote Code Execution Vulnerability |
| CVE-2022-24452 | 7.8 HIGH | HEVC Video Extensions Remote Code Execution Vulnerability |
| CVE-2022-24507 | 7.8 HIGH | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2022-24451 | 7.8 HIGH | VP9 Video Extensions Remote Code Execution Vulnerability |
| CVE-2022-23301 | 7.8 HIGH | HEVC Video Extensions Remote Code Execution Vulnerability |
| CVE-2022-23300 | 7.8 HIGH | Raw Image Extension Remote Code Execution Vulnerability |
| CVE-2022-23296 | 7.8 HIGH | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2022-23295 | 7.8 HIGH | Raw Image Extension Remote Code Execution Vulnerability |
| CVE-2022-23299 | 7.8 HIGH | Windows PDEV Elevation of Privilege Vulnerability |
| CVE-2022-24454 | 7.8 HIGH | Windows Security Support Provider Interface Elevation of Privilege Vulnerability |
Showing top 20 of 70 CVEs. View all on vendor page → →
No comments yet