QID 150664
Date Published: 2023-03-30
QID 150664: Microsoft Exchange Server Multiple Vulnerabilities (ProxyNotShell) (CVE-2022-41040,CVE-2022-41082)
Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft. It runs exclusively on Windows Server operating systems.
Multiple Vulnerabilities are identified in affected versions of Microsoft Exchange Server:
CVE-2022-41040: Elevation of Privilege vulnerability.
CVE-2022-41082: Remote Code Execution (RCE) when PowerShell is accessible to the attacker.
Affected Products:
Exchange Server 2013 CU23
Exchange Server 2016 CU22
Exchange Server 2016 CU23
Exchange Server 2019 CU11
Exchange Server 2019 CU12
QID Detection Logic: (Unauthenticated)
This QID sends a HTTP GET request to "/owa" endpoint and checks for vulnerable version of Microsoft Exchange Server.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary commands on the target system.
For more information regarding these vulnerabilities and patching details please refer Microsoft Security Advisory.
- Microsoft Security Advisory -
msrc.microsoft.com/blog/2022/09/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
CVEs related to QID 150664
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Microsoft Security Advisory |
|