CVE-2022-41040
HIGH KEV RANSOMWAREMicrosoft Exchange ProxyNotShell RCE
Title source: metasploitDescription
Microsoft Exchange Server Elevation of Privilege Vulnerability
Exploits (11)
nomisec
WORKING POC
91 stars
by kljunowsky · remote
https://github.com/kljunowsky/CVE-2022-41040-POC
nomisec
WORKING POC
35 stars
by TaroballzChen · remote
https://github.com/TaroballzChen/CVE-2022-41040-metasploit-ProxyNotShell
nomisec
WORKING POC
by CentarisCyber · poc
https://github.com/CentarisCyber/CVE-2022-41040_Mitigation
metasploit
WORKING POC
EXCELLENT
by Orange Tsai, Spencer McIntyre, DA-0x43-Dx4-DA-Hx2-Tx2-TP-S-Q, Piotr Bazydło, Rich Warren, Soroush Dalili · rubypocwindows
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/exchange_proxynotshell_rce.rb
References (6)
Scores
CVSS v3
8.8
EPSS
0.9415
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-09-30
VulnCheck KEV
2022-09-29
InTheWild.io
2022-09-30
ENISA EUVD
EUVD-2022-44285
Ransomware Use
Confirmed
CWE
CWE-918
Status
published
Products (3)
microsoft/exchange_server
2013 cumulative_update_23
microsoft/exchange_server
2016 cumulative_update_22 (2 CPE variants)
microsoft/exchange_server
2019 cumulative_update_11 (2 CPE variants)
Published
Oct 03, 2022
KEV Added
Sep 30, 2022
Tracked Since
Feb 18, 2026