OWASSRF Explained: Analyzing the Microsoft Exchange RCE Vulnerability
ID: 141d4b25-cd09-513d-94a0-82ca0f608bde
STIX ID: report--141d4b25-cd09-513d-94a0-82ca0f608bde
Feed Name: Huntress Blog
**Huntress (Dec 2022) — OWASSRF Exchange exploit and post-exploitation campaign:** The report describes active in-the-wild exploitation of Microsoft Exchange servers via the OWASSRF chain (CVE-2022-41080/CVE-2022-41082) allowing authenticated OWA sessions to proxy PowerShell Remoting and achieve NT AUTHORITY\SYSTEM code execution; attackers used bitsadmin/PowerShell to deploy rogue ScreenConnect instances and Mimikatz, Huntress provides observed IOCs (IPs, domains, ScreenConnect instance IDs), Sigma detection rules, and patching/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
