ID:8733 - Exploit for Server-Side Request Forgery (SSRF) in Microsoft Exchange Server - CVE-2022-41040
Published: January 11, 2023
Microsoft Exchange Server
Link to public exploit:
Vulnerability description
The disclosed vulnerability allows a remote user to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input within the Exchange OWA Autodiscover service.. A remote user can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker to execute arbitrary code on the target system.
Note, the vulnerability is being actively exploited in the wild.