Remediation Released for Zero-day Vulnerabilities in Microsoft Exchange Server
Microsoft has released remediation for the two exploited vulnerabilities known as ProxyNotShell that concern server-side forgery leading to RCE
Summary
Microsoft has released remediation for the two exploited vulnerabilities known as ProxyNotShell that concern server-side forgery leading to RCE
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation in the wild
Proof-of-concept exploit code has been publicly released and exploitation has been reported in the wild.
Introduction
Microsoft has released security updates to remediate against two previously disclosed and exploited vulnerabilities in Microsoft Exchange Server. The vulnerability known as CVE-2022-41040 concerns server-side request forgery (SSRF), and the second vulnerability, known as CVE-2022-41082, could allow remote code execution (RCE) when PowerShell is accessible to the attacker.
A remote, authenticated attacker could abuse CVE-2022-41040 in order to exploit CVE-2022-41082, which could lead to remote code execution (RCE).
Follow up to previous High Severity Cyber Alert CC-4178
The remediation in this Cyber Alert replaces the guidance previously released in CC-4178. Affected organisations are only required to follow the guidance in this article.
Threat updates
| Date | Update |
|---|---|
| 21 Nov 2022 |
Exploitation and a public proof-of-concept released
This Cyber Alert has been updated to reflect that there has been exploitation in the wild reported and a public proof-of-concept released. |
Remediation advice
Affected organisations are required to read the following security advisories and apply all relevant security updates.
- Microsoft Exchange Server Elevation of Privilege Vulnerability CVE-2022-41040
- Microsoft Exchange Server Remote Code Execution Vulnerability CVE-2022-41082
- Released: November 2022 Exchange Server Security Updates - Microsoft Community Hub
Definitive source of threat updates
- https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
- https://techcommunity.microsoft.com/t5/exchange-team-blog/released-november-2022-exchange-server-security-updates/ba-p/3669045
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41082
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41040
- https://digital.nhs.uk/cyber-alerts/2022/cc-4178
- https://digital.nhs.uk/cyber-alerts/2022/cc-4209
CVE Vulnerabilities
Last edited: 21 November 2022 12:43 pm