CVSS v3.1 Metrics
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Prediction
Documented as more likely to be exploited than 99.6% of known CVEs.
Sep 30, 2022
Oct 21, 2022
Threat Analysis
Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution.
Remediation Directive
Apply updates per vendor instructions.
External Intelligence
https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2022-41082