Server-Side Request Forgery (SSRF) in Microsoft Exchange Server - CVE-2022-41040
Published: September 30, 2022 / Updated: January 11, 2023
Vulnerability details
The disclosed vulnerability allows a remote user to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input within the Exchange OWA Autodiscover service.. A remote user can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker to execute arbitrary code on the target system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2022-41040
Links to Public Exploits and PoC-codes
- Exploit #8733 - CVE-2022-41082-MASS-SCANNER () (January 11, 2023)
- Exploit #8730 - CVE-2022-41040-metasploit-ProxyNotShell () (January 11, 2023)
- Exploit #8636 - Microsoft Exchange ProxyNotShell RCE (November 30, 2022)
- Exploit #8506 - CVE-2022-41040-metasploit-ProxyNotShell (the metasploit script(POC) about CVE-2022-41040. Microsoft Exchange are vulnerable to a server-side request forgery (SSRF) attack. An authenticated attacker can use the vulnerability to elevate privileges.) (October 20, 2022)
- Exploit #8481 - CVE-2022-41040 () (October 16, 2022)
- Exploit #8446 - CVE-2022-41040 (Code set relating to CVE-2022-41040) (October 6, 2022)
- Exploit #8440 - Exploit-CVE-2022-41040-CVE-2022-41082- (Zero-day vulnerabilities affecting Microsoft Exchange Server ) (October 4, 2022)
- Exploit #8432 - nse-exchange (Nmap scripts to detect exchange 0-day (CVE-2022-41082) vulnerability) (October 3, 2022)
- Exploit #8427 - CVE-2022-41082-Scanner (CVE-2022-41082 and CVE-2022-41040 (ProxyNotShell) mass scanner) (October 3, 2022)
External References
- https://gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html
- https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41040
- https://www.zerodayinitiative.com/advisories/ZDI-22-1441/
- https://www.zerodayinitiative.com/advisories/ZDI-22-1595/