AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-42136

HIGH · CVSS 8.8 EPSS 0.87%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-01-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-42136
Severity
HIGH
CVSS
8.8
EPSS
0.87%

Original NVD Description

Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands.