January 2023 Patch Tuesday forecast: Procrastinate at your own risk
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-41040 +1 in the same advisory: …41082 | Server-Side Request Forgery in Microsoft Exchange Server (ProxyNotShell) CVE-2022-41040 is a server-side request forgery (SSRF, CWE-918) vulnerability in Microsoft Exchange Server, publicly tracked under the name "ProxyNotShell" together with CVE-2022-41082. It is triggered when an attacker sends crafted HTTP requests to exposed Exchange web endpoints (such as Autodiscover), causing the server to issue attacker-influenced requests to itself. On its own the SSRF coerces authenticated server-side requests, but when chained with the CVE-2022-41082 remote code execution flaw it gives the attacker code execution on the Exchange server, typically followed by web shells, data access, and — in observed campaigns — ransomware deployment. Organizations running on-premises Microsoft Exchange Server are affected; the source data lists only Microsoft Exchange Server and does not specify affected version ranges, and hosted Exchange Online is a separate product not listed here. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-30 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days; no public PoC is listed. Do: Apply Microsoft's Exchange Server security updates per vendor instructions immediately, as required by the CISA KEV catalog. As interim mitigation, restrict or block untrusted internet access to Exchange web endpoints (e.g., Autodiscover, OWA, ECP), and review IIS logs for suspicious crafted requests indicating SSRF or the chained CVE-2022-41082 exploitation. Given documented ransomware use, prioritize any internet-facing Exchange server and hunt for web shells and post-exploitation activity. | 8.8 group max | 100% | KEV ransomware PoC |
| mass≈250,000+ internet-exposed Exchange servers (public scans of exposed OWA/ECP/Exchange endpoints) | |
| CVE-2022-41080 | Microsoft Exchange Server Privilege Escalation Exploited in Ransomware Campaigns CVE-2022-41080 is an elevation-of-privilege flaw in Microsoft Exchange Server that stems from improper handling of requests to the server's Autodiscover component, allowing an attacker with any valid authenticated mailbox account to escalate privileges on the server. It is triggered by sending crafted authenticated HTTP requests to the Autodiscover endpoint, and it lets attackers bypass the URL-rewrite mitigations defenders had deployed against the earlier ProxyNotShell SSRF. When chained with the related PowerShell remote-code-execution bug CVE-2022-41082, privilege escalation becomes full remote code execution on the Exchange server. Any organization running on-premises Exchange Server with the Autodiscover component reachable — especially internet-exposed OWA/Autodiscover endpoints — is affected. The flaw is actively exploited: it was added to CISA's KEV catalog on 2023-01-10, is known to be used by ransomware operators, and has been tied to the Play ransomware gang, including the attack that took Rackspace's hosted Exchange environment offline. Do: Apply Microsoft Exchange Server security updates per vendor instructions (this CVE was fixed in Microsoft's November 2022 Exchange security updates — verify your servers are fully patched through the January 2023 rollups and that no Exchange builds predate the fix). Until patched, apply and verify the Autodiscover URL-rewrite/allow-list mitigation, knowing this flaw is a known bypass vector, and restrict Autodiscover/OWA exposure where feasible. Hunt for compromise in IIS logs for unusual requests to /autodiscover/autodiscover.json followed by PowerShell (CVE-2022-41082) activity, and treat any suspicious authenticated sessions as potential ransomware precursor activity. | 8.8 | 77% | KEV ransomware |
| large≈10,000–100,000 internet-exposed on-premises Exchange servers |
Full article651 words · extracted from helpnetsecurity.com · click to collapse
The start of a new year means it’s time to start working towards achieving your annual resolutions. Based on the headlines from the December news media, perhaps the most important point is don’t procrastinate! We should all have some sort of goal around improving the speed or efficiency in securing our systems so let’s get too it.

Microsoft disclosed two zero-day vulnerabilities back in September – Exchange Server Elevation of Privilege Vulnerability (CVE-2022-41040) and Exchange Server Remote Code Execution Vulnerability (CVE-2022-41082), associated with the ProxyNotShell attacks. A series of interim mitigations were also provided until the patches were released in November. If you procrastinated to deploy these updates the last two months, you are now running at high risk.
Researchers at Crowdstrike announced a new strain of ransomware called Play is using CVE-2022-41080 to access a PowerShell remote service and then CVE-2022-41082 to run remote code. The most important point here is that this method of access via this new vulnerability completely bypasses the interim mitigations provided by Microsoft; however, if you installed the updates in a timely fashion then you are protected. Don’t procrastinate.
There are business reasons why we can’t often move as fast as we would want to, but when announcements for upcoming changes are provided years in advance we need to plan and respond. It has been three years since Microsoft began their Windows 7 and Server 2008/2008 R2 Extended Security Update (ESU) program and the final security updates for these operating systems will drop next week. While they will continue to run well past the deadline, new vulnerabilities will continue to be discovered and these systems will be running at ever increasing risk of exploitation. Don’t forget about the applications running on them as well.
Google announced they are dropping Chrome support for Windows 7 in Feb 2023 and that Chrome 109 will be the last to support these operating systems. More vendors will soon follow in discontinuing their product support for these operating systems as well, so plan accordingly.
A final reminder that Microsoft is ending support of Basic Authentication for Exchange Online this month. They posted another announcement just prior to the holidays putting everyone on final notice that ‘time is up’. All remaining, affected tenants will be notified via Message Center one week prior to it being disabled and they will need to make the required changes. The announcement contains linked KBs with detailed guidance. You can’t really procrastinate on this one because you will soon lose access to Exchange once Microsoft flips the switch off.
January 2023 Patch Tuesday forecast
- There were no preview updates in December as usual due to the holidays, so the first release of the year is always interesting. Contrary to my prediction, the December Patch Tuesday release was small in terms of CVEs fixed, so I anticipate a high number of CVEs addressed in both the operating systems and applications updates. They may also want to end the ESU with a set of major updates to fix as many issues as possible.
- The new first quarter is here, so expect a major update for Adobe Acrobat and Reader.
- Apple released updates for Ventura, Monterey, Big Sur, iOS, and Safari in mid-December. Unless a new zero-day makes an appearance, it should be quiet in the Mac world next week.
- Google released both Stable Channel ChromeOS 108.0.5359.172 and Long Term Support Channel ChromeOS 102.0.5005.194 late this week so I don’t anticipate any other near-term updates.
- The last updates from Mozilla with reported CVEs are from mid-to-late December for Firefox, Firefox ESR, and Thunderbird. There have been additional releases since then, so we may not see a major update from them next week either.
It’s a new year and time to make a fresh start. Last month I asked you to make some New Year’s resolutions you really want and can achieve, so let’s get started.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/01/06/january-2023-patch-tuesday-forecast/