LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-41040: Microsoft Exchange Server Server-Side Request Forgery Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 30, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Oct 21, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-41040 to its Known Exploited Vulnerabilities catalog on Sep 30, 2022, with a federal patch deadline of Oct 21, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.

CVE-2022-41040 is a server-side request forgery vulnerability in Microsoft Exchange Server, also known as part of the ProxyNotShell attack chain. It allows an attacker to force the Exchange server to make unintended requests, and it can be combined with CVE-2022-41082 to achieve remote code execution. Because Exchange often sits at the center of email and collaboration infrastructure, successful exploitation can give adversaries a foothold for further compromise, including ransomware activity that has been observed in the wild.

Defenders should treat this as a high-priority issue for any organization running on-premises Exchange. Confirm all version and patch details against the official Microsoft advisory, as public technical specifics beyond the CWE and chaining description remain limited here.

How it works

The underlying weakness is CWE-918: server-side request forgery (SSRF). In an SSRF flaw, an attacker supplies a crafted request that causes the vulnerable server to initiate outbound connections or internal requests on the attacker’s behalf. For Microsoft Exchange Server, this means an authenticated or specially positioned attacker can abuse Exchange components to reach internal endpoints or services that would otherwise be inaccessible.

According to CISA, the vulnerability is chainable with CVE-2022-41082. Once the SSRF is leveraged to reach a secondary component, the second flaw enables remote code execution. Exact request formats, authentication requirements, and payload construction are not detailed in the provided facts; treat any public exploit descriptions as unconfirmed until validated against the vendor advisory. The practical result is that an attacker who can trigger the SSRF may escalate to full control of the Exchange host, after which ransomware or data theft becomes feasible.

Am I affected? How to find it in your systems

Microsoft Exchange Server is typically deployed on Windows servers inside corporate networks or hybrid environments that still maintain on-premises mailboxes, Outlook Web Access, or ActiveSync. Inventory every host running the Exchange Server role (Mailbox, Client Access, Edge, etc.).

If your Exchange servers are fully patched according to the vendor timeline and you have no residual unpatched instances, risk is substantially lower. Confirm status against the current Microsoft security update guide.

How to remediate

The primary remediation is to apply the security updates Microsoft released for this vulnerability, following the vendor’s instructions exactly. CISA’s required action is simply: apply updates per vendor instructions.

Once the official patch is applied, re-inventory to confirm no unpatched servers remain.

If you can't patch immediately

If immediate patching is blocked by change windows or compatibility testing, implement compensating controls to reduce the attack surface until the update can be deployed.

These measures lower risk but do not eliminate it; schedule the official update as soon as operationally feasible.

If your data may have been exposed

Because this vulnerability has been chained to remote code execution and has known ransomware use, successful exploitation can lead to full server compromise, credential theft, mailbox access, and subsequent data exfiltration or encryption. If you discover indicators of compromise or confirm that an unpatched Exchange server was reachable by attackers, assume potential exposure of email content, credentials, and any data stored on or accessible from that host. Isolate the affected systems, preserve forensic evidence, and follow your incident-response plan. As a quick personal check, individuals can run a free exposure scan of their email addresses against known breach data sets to see whether their credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Exchange Server
WeaknessCWE-918
Added to CISA KEVSep 30, 2022
Federal patch deadlineOct 21, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities