New 0-Day Vulnerabilities Found in Microsoft Exchange | Huntress
ID: 85d03e85-b005-5c7f-a47c-ce8032df8ad5
STIX ID: report--85d03e85-b005-5c7f-a47c-ce8032df8ad5
Feed Name: Huntress Blog
Threat Score
Huntress investigated reports of new Microsoft Exchange zero-day vulnerabilities—an authenticated SSRF (CVE-2022-41040) and a chained post-auth Remote Code Execution (CVE-2022-41082) enabling PowerShell execution and webshell deployment; Microsoft confirmed the issues, community researchers reported active backdoors on many servers, and confirmed webshell paths and Defender detections are provided alongside containment guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
