CVE-2022-41040 is an Elevation of Privilege vulnerability affecting Microsoft Exchange Server, often exploited in conjunction with CVE-2022-41082 (ProxyNotShell). This high-severity flaw (CVSS 8.8) allows an authenticated attacker to gain elevated privileges remotely over the network with low attack complexity, leading to full compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, including by ransomware groups, and has publicly available exploit modules in Metasploit. The vulnerability has garnered significant community attention and media coverage due to its critical nature and widespread impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.