First published: Fri Sep 30 2022(Updated: )
Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution.
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2013-cumulative_update_23 | |
Microsoft Exchange Server | =2016-cumulative_update_22 | |
Microsoft Exchange Server | =2016-cumulative_update_23 | |
Microsoft Exchange Server | =2019-cumulative_update_11 | |
Microsoft Exchange Server | =2019-cumulative_update_12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41082 is a remote code execution vulnerability in Microsoft Exchange Server.
The severity of CVE-2022-41082 is critical.
CVE-2022-41082 allows authenticated attackers to execute arbitrary code on a vulnerable Microsoft Exchange Server.
Yes, CVE-2022-41082 is chainable with CVE-2022-41040, which also allows for remote code execution.
To fix CVE-2022-41082, apply the latest security updates provided by Microsoft.