Microsoft Exchange On-Prem Zero-Day Vulnerabilities Exploited
ID: e3ea2ccc-0a70-57b5-b979-76adfbb8538b
STIX ID: report--e3ea2ccc-0a70-57b5-b979-76adfbb8538b
Feed Name: Arctic Wolf Blog
GTSC and Microsoft disclosed two on‑premises Microsoft Exchange zero‑day vulnerabilities—CVE-2022-41040 (SSRF) and CVE-2022-41082 (post-auth RCE)—affecting Exchange Server 2013/2016/2019 (Exchange Online not affected). No patches were available at the time; Microsoft is investigating and provided mitigations including an IIS URL rewrite, blocking Remote PowerShell ports (5985/5986), and restricting external access to Exchange servers. The report notes exploitation requires prior authentication and exposed PowerShell Remoting, reducing but not eliminating risk compared to prior Exchange zero-days.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
