Microsoft Exchange Server
CVE-2022-41082 — Microsoft Exchange Server Remote Code Execution Vulnerability
Executive Summary
None
Overview
8
CVSS HIGH
Important
MS Severity
Exploited
MS Exploit Status
Exploitation Detected
MS Exploit Likelihood
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
ATTACK VECTOR
Adjacent_network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Proof-of-Concept
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 7.2
EPSS Score
0.9997
probability of exploitation in the next 30 days
0.99979 percentile - updated 2026-08-14
View on FIRST.org
Affected Products
5 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Microsoft Exchange Server 2013 Cumulative Update 23 | 5019758 (Security Update) |
Important | Remote Code Execution | Yes |
| Microsoft Exchange Server 2016 Cumulative Update 22 | 5019758 (Security Update) |
Important | Remote Code Execution | Yes |
| Microsoft Exchange Server 2016 Cumulative Update 23 | 5019758 (Security Update) |
Important | Remote Code Execution | Yes |
| Microsoft Exchange Server 2019 Cumulative Update 11 | 5019758 (Security Update) |
Important | Remote Code Execution | Yes |
| Microsoft Exchange Server 2019 Cumulative Update 12 | 5019758 (Security Update) |
Important | Remote Code Execution | Yes |
Patches
1 patch
| Article | Type | Restart |
|---|---|---|
5019758 |
Security Update | Yes |
Exploits & PoC
9 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| balki97/OWASSRF-CVE-2022-41082-POC | 93 | 2022-12-22 | PoC for the CVE-2022-41080 , CVE-2022-41082 and CVE-2022-41076 Vulnerabilities Affecting Microsoft Exchange Servers |
| Diverto/nse-exchange | 82 | 2022-10-01 | Nmap scripts to detect exchange 0-day (CVE-2022-41082) vulnerability |
| notareaperbutDR34P3r/http-vuln-CVE-2022-41082 | 3 | 2022-11-14 | Microsoft Exchange Server Remote Code Execution Vulnerability. |
| soltanali0/CVE-2022-41082 | 3 | 2024-10-24 | CVE-2022-41082-poc |
| sikkertech/CVE-2022-41082 | 2 | 2022-12-01 | Exchange CVE '22 |
| SUPRAAA-1337/CVE-2022-41082 | 2 | 2023-09-03 | |
| bigherocenter/CVE-2022-41082-POC | 1 | 2023-02-21 | |
| notareaperbutDR34P3r/vuln-CVE-2022-41082 | 0 | 2023-03-22 | https & http |
| CyprianAtsyor/LetsDefend-CVE-2022-41082-Exploitation-Attempt | 0 | 2025-05-16 |
Detection Rules
Detection availableCommunity detection & vulnerability-scanning rules aggregated from Sigma and Nuclei templates. Validate and tune to your environment before deploying.
Sigma rules 7
OWASSRF Exploitation Attempt Using Public POC - Proxy
critical
OWASSRF Exploitation Attempt Using Public POC - Webserver
critical
Potential OWASSRF Exploitation Attempt - Proxy
high
Potential OWASSRF Exploitation Attempt - Webserver
high
Suspicious ASPX File Drop by Exchange
high
Chopper Webshell Process Pattern
high
Suspicious File Drop by Exchange
medium
Acknowledgments
Piotr Bazydlo (@chudypb)
DA-0x43-Dx4-DA-Hx2-Tx2-TP-S-Q from GTSC working with Trend Micro Zero Day Initiative
References
On This Page