ZeroHour

CVE-2022-41082

KEV ransomware PoC mass1

Authenticated RCE in Microsoft Exchange Server (ProxyNotShell)

CISA: Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 3.1
8.0 high
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2022-41082, dubbed "ProxyNotShell," is an authenticated remote code execution vulnerability in Microsoft Exchange Server; the associated CWE-502 indicates deserialization of untrusted data. It is exploited in a chain with CVE-2022-41040, a server-side request forgery in Exchange that lets an unauthenticated attacker reach the vulnerable endpoint via crafted web requests and trigger the remote code execution. Successful exploitation gives an attacker the ability to run code on the Exchange server, and CISA notes known ransomware use. Any organization running an on-premises Microsoft Exchange Server deployment is potentially affected, with the specific version ranges per Microsoft's advisory. The flaw is actively exploited in the wild: it was added to CISA KEV on 2022-09-30 with ransomware use known, and EPSS assigns a 100% probability of exploitation within 30 days, even though no public proof-of-concept is known.

What to do: Apply Microsoft's Exchange security updates immediately per vendor instructions, as required by CISA's KEV listing (added 2022-09-30). If patching is delayed, apply Microsoft's interim mitigations that restrict access to the Autodiscover endpoint used in the CVE-2022-41040 SSRF chain, and review web and PowerShell logs for signs of compromise given the known ransomware use.

Affected
Microsoft Exchange Server
Estimated exposure
massorder of 10^5 — hundreds of thousands of internet-exposed on-prem Exchange servers plausibly affected — Public internet-wide scans of Exchange's web endpoints (OWA/EWS/Autodiscover) during the 2022 Exchange incidents repeatedly counted on the order of hundreds of thousands of exposed on-prem servers, and because this flaw is chainable from…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Exchange Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
exchange server
Weakness
CWE-502
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news