logo

ProxyNotShell Proof Of Concept Now Public

ID: fadf70fc-aacf-5009-8dc1-4d54aed94127

STIX ID: report--fadf70fc-aacf-5009-8dc1-4d54aed94127

Feed Name: Censys Blog

Threat Score
78/100

Date Published: 2022-11-22

Date Updated: 2026-04-27

...
...

Censys reports on ProxyNotShell — a ProxyShell-like chain of Exchange vulnerabilities (CVE-2022-41040 and CVE-2022-41082) that enable remote code execution on Exchange Server 2013/2016/2019. A Chinese nation-state actor has been observed exploiting these flaws in the wild; a public proof-of-concept was released, increasing the risk of wider abuse against Internet-exposed Exchange servers. Microsoft released patches (Nov 3, 2022) and Censys provides detection dashboards and search queries to identify affected hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.