Microsoft Exchange Server
CVE-2022-41040 — Microsoft Exchange Server Elevation of Privilege Vulnerability
Executive Summary
None
Overview
8.8
CVSS HIGH
Critical
MS Severity
Exploited
MS Exploit Status
Exploitation Detected
MS Exploit Likelihood
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Proof-of-Concept
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 7.9
EPSS Score
0.99956
probability of exploitation in the next 30 days
0.99975 percentile - updated 2026-08-14
View on FIRST.org
Affected Products
5 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Microsoft Exchange Server 2013 Cumulative Update 23 | 5019758 (Security Update) |
Critical | Elevation of Privilege | Yes |
| Microsoft Exchange Server 2016 Cumulative Update 22 | 5019758 (Security Update) |
Critical | Elevation of Privilege | Yes |
| Microsoft Exchange Server 2016 Cumulative Update 23 | 5019758 (Security Update) |
Critical | Elevation of Privilege | Yes |
| Microsoft Exchange Server 2019 Cumulative Update 11 | 5019758 (Security Update) |
Critical | Elevation of Privilege | Yes |
| Microsoft Exchange Server 2019 Cumulative Update 12 | 5019758 (Security Update) |
Critical | Elevation of Privilege | Yes |
Patches
1 patch
| Article | Type | Restart |
|---|---|---|
5019758 |
Security Update | Yes |
Exploits & PoC
9 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| kljunowsky/CVE-2022-41040-POC | 91 | 2022-10-09 | CVE-2022-41040 - Server Side Request Forgery (SSRF) in Microsoft Exchange Server |
| TaroballzChen/CVE-2022-41040-metasploit-ProxyNotShell | 35 | 2022-10-20 | the metasploit script(POC) about CVE-2022-41040. Microsoft Exchange are vulnerable to a server-side request forgery (SSRF) attack. An authenticated attacker can use the vulnerability to elevate privil |
| numanturle/CVE-2022-41040 | 19 | 2022-10-02 | CVE-2022-41040 nuclei template |
| r3dcl1ff/CVE-2022-41040 | 5 | 2022-10-04 | mitigation script for MS Exchange server vuln |
| d3duct1v/CVE-2022-41040 | 5 | 2022-10-06 | Code set relating to CVE-2022-41040 |
| rjsudlow/proxynotshell-IOC-Checker | 5 | 2022-10-09 | Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082) |
| ITPATJIDR/CVE-2022-41040 | 1 | 2022-10-14 | |
| CentarisCyber/CVE-2022-41040_Mitigation | 0 | 2022-10-03 | |
| 0-Gram/CVE-2022-41040 | 0 | 2024-11-23 |
Detection Rules
Detection availableCommunity detection & vulnerability-scanning rules aggregated from Sigma and Nuclei templates. Validate and tune to your environment before deploying.
Sigma rules 3
Acknowledgments
DA-0x43-Dx4-DA-Hx2-Tx2-TP-S-Q from GTSC working with Trend Micro Zero Day Initiative
References
On This Page