CISA Known Exploited Vulnerability

CVE-2022-41040 Ransomware

Microsoft · Exchange Server

Microsoft Exchange Server Server-Side Request Forgery Vulnerability

Date added
BOD 22-01 due date
CWE CWE-918
Ransomware Known

CISA description

Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.

Required action

Apply updates per vendor instructions.