Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2022-41040

Microsoft | Exchange ServerAdded 2022-09-30Remediation Deadline 2022-10-21Active Ransomware Campaign

Microsoft Exchange Server Server-Side Request Forgery Vulnerability

Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-918

References