CVE-2022-41040

8.8HIGH

Microsoft Exchange Server Elevation of Privilege Vulnerability

发布于: 10/3/2022更新于: 10/30/2025

CISA已知被利用漏洞

Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.

所需操作:

Apply updates per vendor instructions.

截止日期:

2022-10-21

已知勒索软件使用

描述

Microsoft Exchange Server Elevation of Privilege Vulnerability

AI分析AI驱动

受影响产品

microsoftexchange_server
2013
microsoftexchange_server
2016
microsoftexchange_server
2016
microsoftexchange_server
2019
microsoftexchange_server
2019

参考资料