HIGH
CVE-2022-41040
CVSS
8.8
KEV
Description
Microsoft Exchange Server Elevation of Privilege Vulnerability
Summary dbcve.org
CVE-2022-41040 is an elevation of privilege vulnerability in Microsoft Exchange Server that allows an authenticated attacker to execute arbitrary code via specially crafted PowerShell remoting requests. This vulnerability was actively exploited in the wild as part of the ProxyNotShell attacks, often chained with CVE-2022-41082 for remote code execution.
Mitigation
Apply the November 2022 cumulative update or later for Exchange Server. As a temporary workaround, disable remote PowerShell access for non-admin users or implement URL rewrite rules to block known attack patterns.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
99.96%
Probability of exploitation in next 30 days
100th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41040
Patch, Vendor Advisory
http://packetstormsecurity.com/files/170066/Microsoft-Exchange-ProxyNotShell-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41040
Mitigation, Patch, Vendor Advisory
https://www.kb.cert.org/vuls/id/915563
Third Party Advisory, US Government Resource
https://www.secpod.com/blog/microsoft-november-2022-patch-tuesday-patches-65-vulnerabilities-including-6-zero-days/
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-41040
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.