#VU69097 Permissions, Privileges, and Access Controls in Microsoft Exchange Server - CVE-2022-41080
Published: November 8, 2022 / Updated: December 28, 2022
Microsoft Exchange Server
Microsoft
Description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to application does not properly impose security restrictions. A remote authenticated user can escalate privileges within the Exchange server.
Note, this vulnerability is suspected to be used in a new exploit method bypasses URL rewrite mitigations for the Autodiscover endpoint provided by Microsoft in response to ProxyNotShell.