{"cvss":8.8,"datePublished":"2023-01-10","dateUpdated":"2023-01-10","description":"Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.","dueDate":"2023-01-31","id":"CVE-2022-41080","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Known","notes":"https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41080;  https://nvd.nist.gov/vuln/detail/CVE-2022-41080","product":"Exchange Server","requiredAction":"Apply updates per vendor instructions.","severity":"HIGH","source":"cisa_known_exploited","title":"Microsoft Exchange Server Privilege Escalation Vulnerability","vendor":"Microsoft"}