Junglewise Threat Intelligence

CVE-2022-41082: Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2022-41082 · Severity: critical · CVSS 8 · Exploited in the wild · Published 2022-09-30

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server contains a remote code execution vulnerability, dubbed 'ProxyNotShell', caused by the deserialization of untrusted data. The vulnerability is chainable with CVE-2022-41040 and allows an authenticated attacker to execute arbitrary code on the server.

Affected products

  • Microsoft Exchange Server

Timeline

  • 2022-09-30: disclosed
  • 2022-09-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-09-30: exploited: Reported as exploited in the wild at time of publication.

Related threats