First published: Fri Sep 30 2022(Updated: )
Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2013-cumulative_update_23 | |
Microsoft Exchange Server | =2016-cumulative_update_22 | |
Microsoft Exchange Server | =2016-cumulative_update_23 | |
Microsoft Exchange Server | =2019-cumulative_update_11 | |
Microsoft Exchange Server | =2019-cumulative_update_12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41040 is a server-side request forgery vulnerability found in Microsoft Exchange Server.
CVE-2022-41040 allows an attacker to forge requests and potentially access internal resources.
Yes, CVE-2022-41040 can be exploited remotely.
To mitigate CVE-2022-41040, apply the security updates provided by Microsoft and follow their guidance.
You can find more information about CVE-2022-41040 in the Microsoft Security Response Center blog post.