CVE-2022-41040

8.8HIGH

Microsoft Exchange Server Elevation of Privilege Vulnerability

게시됨: 10/3/2022업데이트됨: 10/30/2025

CISA 알려진 악용 취약점

Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.

필요한 조치:

Apply updates per vendor instructions.

마감일:

2022-10-21

알려진 랜섬웨어 사용

설명

Microsoft Exchange Server Elevation of Privilege Vulnerability

AI 분석AI 기반

영향받는 제품

microsoftexchange_server
2013
microsoftexchange_server
2016
microsoftexchange_server
2016
microsoftexchange_server
2019
microsoftexchange_server
2019

참조