HIGH

CVE-2022-41040

Microsoft Exchange Server 2022-10-03 CVSS v3.1
CVSS
8.8
KEV

Description

Microsoft Exchange Server Elevation of Privilege Vulnerability

Summary dbcve.org

CVE-2022-41040 is an elevation of privilege vulnerability in Microsoft Exchange Server that allows an authenticated attacker to execute arbitrary code via specially crafted PowerShell remoting requests. This vulnerability was actively exploited in the wild as part of the ProxyNotShell attacks, often chained with CVE-2022-41082 for remote code execution.

Mitigation

Apply the November 2022 cumulative update or later for Exchange Server. As a temporary workaround, disable remote PowerShell access for non-admin users or implement URL rewrite rules to block known attack patterns.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

99.96%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE