CVE-2022-41040: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.
Other sources
Microsoft Exchange Server Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.0986.036Patch KB5019758 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2375.037Patch KB5019758 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.016Patch KB5019758 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1118.020Patch KB5019758 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.00.1497.044Patch KB5019758
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-41040?
CVE-2022-41040 is a server-side request forgery vulnerability found in Microsoft Exchange Server.
What is the impact of CVE-2022-41040?
CVE-2022-41040 allows an attacker to forge requests and potentially access internal resources.
Is CVE-2022-41040 exploitable remotely?
Yes, CVE-2022-41040 can be exploited remotely.
How can I mitigate CVE-2022-41040?
To mitigate CVE-2022-41040, apply the security updates provided by Microsoft and follow their guidance.
Where can I find more information about CVE-2022-41040?
You can find more information about CVE-2022-41040 in the Microsoft Security Response Center blog post.