OWASSRF, a new exploit for Exchange vulnerabilities, exploited in the wild: everything you need to know
ID: e43ad75a-da4e-5307-9f9d-445a165467f0
STIX ID: report--e43ad75a-da4e-5307-9f9d-445a165467f0
Feed Name: Wiz Blog
Researchers discovered OWASSRF, a new exploit method chaining CVE-2022-41080 and CVE-2022-41082 to bypass ProxyNotShell mitigations and achieve remote code execution through Outlook Web Access; the Play ransomware group has been observed using this technique against on-premises Microsoft Exchange Server 2013/2016/2019 instances (prior to KB5019758). The report includes a timeline of discovery, affected products, recommended mitigations (apply KB5019758 or disable OWA), regionally observed targeting (Latin America, notably Brazil), and published TTPs and IOCs for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
