EXPOSURES › CVE-2022-41040
CVE-2022-41040
CRITICAL ⌖ ON CISA KEV · EXPLOITEDMicrosoft Exchange Server's ProxyNotShell SSRF vulnerability, when chained with CVE-2022-41082, enables remote code execution and was actively exploited in the wild for ransomware attacks.
Microsoft Exchange Server suffered a critical SSRF vulnerability (CVE-2022-41040) dubbed ProxyNotShell, which is chainable with CVE-2022-41082 to achieve remote code execution. This failure is highly relevant to DIB organizations because it was actively exploited in the wild for ransomware, demonstrating that unpatched or outdated Exchange servers remain a severe threat. Organizations must ensure all Exchange servers are patched to the latest version and that legacy versions like Exchange 2019 are decommissioned or isolated.
Shame score — The vulnerability was actively exploited in the wild for ransomware, indicating a severe and avoidable failure in Microsoft's security posture and patch management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |