logo

OWASSRF Explained: Analyzing the Microsoft Exchange RCE Vulnerability

ID: 141d4b25-cd09-513d-94a0-82ca0f608bde

STIX ID: report--141d4b25-cd09-513d-94a0-82ca0f608bde

Feed Name: Huntress Blog

Threat Score
80/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

**Huntress (Dec 2022) — OWASSRF Exchange exploit and post-exploitation campaign:** The report describes active in-the-wild exploitation of Microsoft Exchange servers via the OWASSRF chain (CVE-2022-41080/CVE-2022-41082) allowing authenticated OWA sessions to proxy PowerShell Remoting and achieve NT AUTHORITY\SYSTEM code execution; attackers used bitsadmin/PowerShell to deploy rogue ScreenConnect instances and Mimikatz, Huntress provides observed IOCs (IPs, domains, ScreenConnect instance IDs), Sigma detection rules, and patching/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.