CVE-2022-41080CISA KEVEPSS p99.5%

CVE-2022-41080Microsoft Exchange Server Privilege Escalation Vulnerability

Microsoft / Exchange Server

Description

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.

Scoring

CVSS 8.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS77.33% probability of exploitation · percentile 99.5% · 2026-08-03T12:00:16Z
Last modified2026-06-17

CISA KEV entry

Added to KEV: 2023-01-10

(incoming)1

TypeTargetConfidenceTier
KEVEntryMicrosoft Exchange Server Privilege Escalation Vulnerabilitykev-cve-2022-410800%live

Related by meaning· 3

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE
Microsoft Exchange Server Server-Side Request Forgery Vulnerability
CVE
Microsoft Exchange Server Information Disclosure Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.