KEV · Actively exploited
CVE-2022-41080
CRITICAL 8.8
KEV
Microsoft Exchange Server Elevation of Privilege Vulnerability
EPSS
93.80%
exploit likely
percentile 99.9%
CISA Known Exploited Vulnerability
- Added to KEV
- 2023-01-10
- Remediation deadline
- 2023-01-31
- Required action
- Apply updates per vendor instructions.
- Ransomware
- Yes, known ransomware campaign