Updated Guidance Microsoft Exchange Zero-Day
ID: 5fd30d86-f74f-56aa-bd01-838563afb845
STIX ID: report--5fd30d86-f74f-56aa-bd01-838563afb845
Feed Name: Arctic Wolf Blog
Threat Score
This advisory summarizes active exploitation of two Microsoft Exchange zero-days (CVE-2022-41040 SSRF and CVE-2022-41082 RCE) and provides mitigation steps: run Microsoft's EOMTv2 URL-rewrite mitigation (or apply the manual IIS URL Rewrite rule), install the IIS URL Rewrite module as recommended, and disable remote PowerShell for non-admins; it also notes observed scanning and potential bypass techniques and clarifies Exchange Online is not affected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
