CVE-2022-42136
Status: ModifiedHigh (8.8)—
Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 8.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.88%
- Percentile among all scored CVEs: 58
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-22
- CWE-22
References
Raw JSON (NVD)
Show
{
"id": "CVE-2022-42136",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-42136",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-04-07T18:56:43.334542Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2023-01-13T21:15:15.523",
"references": [
{
"url": "https://pastebin.com/ahLNMf5n",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.mailenable.com/kb/content/article.asp?ID=ME020737",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://pastebin.com/ahLNMf5n",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.mailenable.com/kb/content/article.asp?ID=ME020737",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands."
},
{
"lang": "es",
"value": "Los usuarios de correo autenticados, en circunstancias específicas, podían agregar archivos con contenido no depurado en carpetas públicas a las que el usuario de IIS tenía permiso para acceder. Esa acción podría llevar a un atacante a almacenar código arbitrario en esos archivos y ejecutar comandos RCE."
}
],
"lastModified": "2026-06-17T05:04:25.630",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0BD1DC6B-569B-4A68-A940-8DD7D46B0EC7",
"versionEndExcluding": "8.66"
},
{
"criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise_premium:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F00FBB02-0396-48FD-A212-B8AA0EED5EB1",
"versionEndExcluding": "8.66"
},
{
"criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:professional:*:*:*",
"vulnerable": true,
"matchCriteriaId": "04012D59-A1A5-4E0D-9D09-B916DF4109C7",
"versionEndExcluding": "8.66"
},
{
"criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:standard:*:*:*",
"vulnerable": true,
"matchCriteriaId": "236A06C3-A366-46E8-AA7A-6BB0076B747F",
"versionEndExcluding": "8.66"
},
{
"criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FB5FA14B-9800-4944-914B-6F5EC3AFE2D3",
"versionEndExcluding": "9.85",
"versionStartIncluding": "9.0"
},
{
"criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise_premium:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4335FB0F-3311-4DB4-82F7-A1951FD2972C",
"versionEndExcluding": "9.85",
"versionStartIncluding": "9.0"
},
{
"criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:professional:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12E681AC-2B1C-4848-A7F3-D32412F971E5",
"versionEndExcluding": "9.85",
"versionStartIncluding": "9.0"
},
{
"criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:standard:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9DAB75C2-9F57-4E54-80EC-B69147E619D1",
"versionEndExcluding": "9.85",
"versionStartIncluding": "9.0"
},
{
"criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7BF6CDCE-2212-49CF-ADA1-F066D126B970",
"versionEndExcluding": "10.42",
"versionStartIncluding": "10.00"
},
{
"criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise_premium:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DD783D53-EEA4-4DBC-B105-E224E4AE978B",
"versionEndExcluding": "10.42",
"versionStartIncluding": "10.00"
},
{
"criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:professional:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE07E64E-C8C4-40D7-AF5D-54C684CF29C8",
"versionEndExcluding": "10.42",
"versionStartIncluding": "10.00"
},
{
"criteria": "cpe:2.3:a:mailenable:mailenable:*:*:*:*:standard:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D2D9F41A-E2A3-495C-90A7-F56104291EDA",
"versionEndExcluding": "10.42",
"versionStartIncluding": "10.00"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}