Skip to content
COOEY

EXPOSURES › CVE-2022-41040

CVE-2022-41040

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-09-30 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-41040 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Microsoft Exchange Server's ProxyNotShell SSRF vulnerability, when chained with CVE-2022-41082, enables remote code execution and was actively exploited in the wild for ransomware attacks.

Microsoft Exchange Server suffered a critical SSRF vulnerability (CVE-2022-41040) dubbed ProxyNotShell, which is chainable with CVE-2022-41082 to achieve remote code execution. This failure is highly relevant to DIB organizations because it was actively exploited in the wild for ransomware, demonstrating that unpatched or outdated Exchange servers remain a severe threat. Organizations must ensure all Exchange servers are patched to the latest version and that legacy versions like Exchange 2019 are decommissioned or isolated.

Shame score — The vulnerability was actively exploited in the wild for ransomware, indicating a severe and avoidable failure in Microsoft's security posture and patch management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized