Junglewise Threat Intelligence

CVE-2022-41040: Microsoft Exchange Server Server-Side Request Forgery Vulnerability

CVE-2022-41040 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-09-30

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability known as 'ProxyNotShell'. An authenticated attacker can leverage this to gain elevated privileges and potentially chain it with CVE-2022-41082 for remote code execution.

Affected products

  • Microsoft Exchange Server

Timeline

  • 2022-09-30: disclosed: Vulnerability published and added to CISA KEV catalog.
  • 2022-09-30: exploited: Reported as exploited in the wild at the time of publication.
  • 2022-11-08: patched: Microsoft released official patches during November Patch Tuesday.

Related threats