CVE-2022-41040: Microsoft Exchange Server Server-Side Request Forgery
Microsoft Exchange Server Server-Side Request Forgery Vulnerability. Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.
- CISA KEV-listed (remediation due 2022-10-21)
- used in ransomware campaigns
- EPSS 94.1% (99.9% percentile)