Executive brief
Microsoft Exchange Server contains a remote code execution vulnerability, dubbed 'ProxyNotShell', caused by the deserialization of untrusted data. The vulnerability is chainable with CVE-2022-41040 and allows an authenticated attacker to execute arbitrary code on the server.
Affected products
- Microsoft Exchange Server
Timeline
- 2022-09-30: disclosed
- 2022-09-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-09-30: exploited: Reported as exploited in the wild at time of publication.