ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

MS Exchange zero-days: The calm before the storm?

criticalRansomware exploited in the wildimportance 60CVE-2022-41040CVE-2022-41082

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-41040
+1 in the same advisory: …41082
Server-Side Request Forgery in Microsoft Exchange Server (ProxyNotShell)

CVE-2022-41040 is a server-side request forgery (SSRF, CWE-918) vulnerability in Microsoft Exchange Server, publicly tracked under the name "ProxyNotShell" together with CVE-2022-41082. It is triggered when an attacker sends crafted HTTP requests to exposed Exchange web endpoints (such as Autodiscover), causing the server to issue attacker-influenced requests to itself. On its own the SSRF coerces authenticated server-side requests, but when chained with the CVE-2022-41082 remote code execution flaw it gives the attacker code execution on the Exchange server, typically followed by web shells, data access, and — in observed campaigns — ransomware deployment. Organizations running on-premises Microsoft Exchange Server are affected; the source data lists only Microsoft Exchange Server and does not specify affected version ranges, and hosted Exchange Online is a separate product not listed here. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-30 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days; no public PoC is listed.

Do: Apply Microsoft's Exchange Server security updates per vendor instructions immediately, as required by the CISA KEV catalog. As interim mitigation, restrict or block untrusted internet access to Exchange web endpoints (e.g., Autodiscover, OWA, ECP), and review IIS logs for suspicious crafted requests indicating SSRF or the chained CVE-2022-41082 exploitation. Given documented ransomware use, prioritize any internet-facing Exchange server and hunt for web shells and post-exploitation activity.

8.8
group max
100% KEV ransomware PoC
  • Microsoft Exchange Server
mass≈250,000+ internet-exposed Exchange servers (public scans of exposed OWA/ECP/Exchange endpoints)
Full article466 words · extracted from helpnetsecurity.com · click to collapse

CVE-2022-41040 and CVE-2022-41082, the two exploited MS Exchange zero-days that still have no official fix, have been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog.

MS Exchange CVE-2022-41040 CVE-2022-41082

But mitigating the risk of exploitation until patches are ready will require patience and doggedness, as Microsoft is still revising its advice to admins and network defenders, and still working on the patches.

Exchange zero-days: The current situation

CVE-2022-41040 and CVE-2022-41082 have been publicly documented last Wednesday, by researchers with Vietnamese company GTSC, and Microsoft soon after sprung into (discernible) action by offering customer guidance, followed by an analysis of the attacks exploiting the two vulnerabilities.

Several changes have been made to the documents since then, after the company found and other researchers pointed out several shortcomings:

T'is fixed, hoorah. https://t.co/BxQFs4iMZy

— Kevin Beaumont (@GossiTheDog) October 1, 2022

For the record this is the section Microsoft removed from the ProxyNotShell blog, and didn’t document they had removed it.

If you made firewall changes to prevent RCE, it didn’t work. https://t.co/p2ClqcLyZE pic.twitter.com/rxokkWz4xz

— Kevin Beaumont (@GossiTheDog) October 1, 2022

And the problems are far from over – defenders should expect more changes soon:

If you are relying on the MS mitigation for #ProxyNotShell, it doesn’t work, I’ve verified. MS might want to read the Exchange source code. https://t.co/5ZYrvUTI8q

— Kevin Beaumont (@GossiTheDog) October 3, 2022

That last tweet refers to the PowerShell script delivering mitigation via the Exchange Emergency Mitigation (EM) service.

What should you do?

Microsoft says its threat analysts observed “activity related to a single activity group in August 2022 that achieved initial access and compromised Exchange servers by chaining CVE-2022-41040 and CVE-2022-41082 in a small number of targeted attacks,” and that the attackers breached fewer than 10 organizations globally.

“MSTIC assesses with medium confidence that the single activity group is likely to be a state-sponsored organization,” they added.

The other good news is there are still no public exploits for the two vulnerabilities.

But, Microsoft says, “Prior Exchange vulnerabilities that require authentication have been adopted into the toolkits of attackers who deploy ransomware, and these vulnerabilities are likely to be included in similar attacks due to the highly privileged access Exchange systems confer onto an attacker.”

Enterprise defenders should expect trouble via this attack path in the near future, it seems, so keeping abreast of the changing situation and springing into action as quickly as possible once the patches are made available is advised.

UPDATE (October, 2022, 06:18 a.m. ET):

Scammers have started impersonating security researchers and offering non-existing PoC exploits for CVE-2022-41082 for sale via GitHub:

This is related to what appears to be numerous repos being made for vulns with no patch available offering what looks like a PoC in exchange for crypto (scam) https://t.co/HJTrtEqFtH

— Ryan (@allthevulns22) September 30, 2022

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/10/03/ms-exchange-cve-2022-41040-cve-2022-41082/