CVE-2022-41040

8.8HIGH

Microsoft Exchange Server Elevation of Privilege Vulnerability

Publicado: 10/3/2022Actualizado: 10/30/2025

Vulnerabilidad Explotada Conocida (CISA)

Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.

Acción Requerida:

Apply updates per vendor instructions.

Fecha Límite:

2022-10-21

Uso de Ransomware Conocido

Descripción

Microsoft Exchange Server Elevation of Privilege Vulnerability

Análisis IAImpulsado por IA

Productos Afectados

microsoftexchange_server
2013
microsoftexchange_server
2016
microsoftexchange_server
2016
microsoftexchange_server
2019
microsoftexchange_server
2019

Referencias