Microsoft Exchange Exploit Chain via "OWASSRF" Leads to RCE
ID: 0faf2d49-3123-500e-9c93-467cf6ad5eda
STIX ID: report--0faf2d49-3123-500e-9c93-467cf6ad5eda
Feed Name: Arctic Wolf Blog
Threat Score
Arctic Wolf advises organizations running Microsoft Exchange Server (on-premises or hybrid) to apply November security updates (KB5019758) to address CVE-2022-41080 and CVE-2022-41082—vulnerabilities that have been used in intrusions and are actively exploited—and provides additional mitigations such as disabling on-prem Exchange web services, restricting external access, and disabling remote PowerShell for non-admins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
