CVE-2022-41082
HIGH KEV RANSOMWAREMicrosoft Exchange Server - RCE
Title source: llmDescription
Microsoft Exchange Server Remote Code Execution Vulnerability
Exploits (12)
nomisec
WORKING POC
95 stars
by balki97 · remote-auth
https://github.com/balki97/OWASSRF-CVE-2022-41082-POC
nomisec
SCANNER
3 stars
by notareaperbutDR34P3r · infoleak
https://github.com/notareaperbutDR34P3r/http-vuln-CVE-2022-41082
nomisec
WORKING POC
1 stars
by bigherocenter · remote-auth
https://github.com/bigherocenter/CVE-2022-41082-POC
nomisec
WRITEUP
by CyprianAtsyor · poc
https://github.com/CyprianAtsyor/LetsDefend-CVE-2022-41082-Exploitation-Attempt
nomisec
SCANNER
by notareaperbutDR34P3r · infoleak
https://github.com/notareaperbutDR34P3r/vuln-CVE-2022-41082
patchapalooza
SCANNER
by NitinYadav00 · remote
https://github.com/NitinYadav00/Exploit-Microsoft-Exchange-Server-
metasploit
WORKING POC
EXCELLENT
by Orange Tsai, Spencer McIntyre, DA-0x43-Dx4-DA-Hx2-Tx2-TP-S-Q, Piotr Bazydło, Rich Warren, Soroush Dalili · rubypocwindows
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/exchange_proxynotshell_rce.rb
References (8)
Scores
CVSS v3
8.0
EPSS
0.9169
EPSS Percentile
99.7%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2022-09-30
VulnCheck KEV
2022-09-29
InTheWild.io
2022-09-30
ENISA EUVD
EUVD-2022-44326
Ransomware Use
Confirmed
Classification
CWE
CWE-502
Status
published
Affected Products (5)
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
Timeline
Published
Oct 03, 2022
KEV Added
Sep 30, 2022
Tracked Since
Feb 18, 2026