CVE-2022-41082: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution.
Other sources
Microsoft Exchange Server Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1118.020Patch KB5019758 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2375.037Patch KB5019758 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.00.1497.044Patch KB5019758 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.016Patch KB5019758 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.0986.036Patch KB5019758
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-41082?
CVE-2022-41082 is a remote code execution vulnerability in Microsoft Exchange Server.
What is the severity of CVE-2022-41082?
The severity of CVE-2022-41082 is critical.
How does CVE-2022-41082 work?
CVE-2022-41082 allows authenticated attackers to execute arbitrary code on a vulnerable Microsoft Exchange Server.
Is CVE-2022-41082 chainable with another vulnerability?
Yes, CVE-2022-41082 is chainable with CVE-2022-41040, which also allows for remote code execution.
How can I fix CVE-2022-41082?
To fix CVE-2022-41082, apply the latest security updates provided by Microsoft.