EXPOSURES › CVE-2022-41082
CVE-2022-41082
CRITICAL ⌖ ON CISA KEV · EXPLOITEDMicrosoft Exchange Server's ProxyNotShell vulnerability allowed authenticated remote code execution, enabling ransomware attacks when chained with CVE-2022-41040.
Microsoft Exchange Server suffered a critical remote code execution flaw dubbed ProxyNotShell, which could be chained with CVE-2022-41040 to achieve full remote code execution. This systemic validation and deserialization issue allowed attackers to execute arbitrary code on the server, leading to widespread ransomware incidents. DIB organizations must ensure all Exchange Server instances are patched to the latest version, as older versions like Exchange 2019 no longer receive public security updates.
Shame score — The vulnerability was actively exploited in the wild, linked to ransomware, and stemmed from systemic issues in Microsoft's validation logic, indicating a severe avoidable failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |