Vulnerability detail
Enriched intelligence for a single CVE
High
CVE-2022-41082
PUBLISHEDMicrosoft Exchange Server Remote Code Execution Vulnerability
- Vendor
- Microsoft
- Product
- Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 23
- Published
- Oct 03, 2022
- EPSS
- —
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
CVSS scores
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
SSVC decision points
- Exploitation
- active
- Automatable
- No
- Technical impact
- total
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | Sep 30, 2022 |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/exchange_proxynotshell_rce.rb | Apr 28, 2025 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2023-09-03 20:55:20 UTC · 2 stars
github · Created 2022-12-22 09:35:26 UTC · 92 stars
PoC for the CVE-2022-41080 , CVE-2022-41082 and CVE-2022-41076 Vulnerabilities Affecting Microsoft Exchange Servers
github · Created 2022-11-14 08:31:16 UTC · 3 stars
Microsoft Exchange Server Remote Code Execution Vulnerability.
Timeline
-
CVE ID Reserved
-
Exploit Used in Malware
-
Added to KEVIntel
-
CVE Published to Public
-
Detected by Metasploit