Executive brief
Microsoft Exchange Server is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability known as 'ProxyNotShell'. An authenticated attacker can leverage this to gain elevated privileges and potentially chain it with CVE-2022-41082 for remote code execution.
Affected products
- Microsoft Exchange Server
Timeline
- 2022-09-30: disclosed: Vulnerability published and added to CISA KEV catalog.
- 2022-09-30: exploited: Reported as exploited in the wild at the time of publication.
- 2022-11-08: patched: Microsoft released official patches during November Patch Tuesday.