Emerging Threats: Microsoft Exchange On-Prem Zero-Days
ID: 07ebbdc2-ca93-512e-af60-94f42156032f
STIX ID: report--07ebbdc2-ca93-512e-af60-94f42156032f
Feed Name: Expel Blog
**Executive summary:** Microsoft confirmed two on-premises Exchange zero-day vulnerabilities (CVE-2022-41040 — SSRF, and CVE-2022-41082 — RCE) being used together in active attacks; no patch was available at the time and both issues require authenticated access. The report recommends immediate mitigations (block exposed Remote PowerShell, review and restrict OWA exposure, verify hybrid deployment asset inventories), monitoring for IOCs including web shells, and continuous behavioral detection to reduce risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
