CVE-2022-41082

high

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

From the Tenable Blog

CVE-2022-41040 and CVE-2022-41082: ProxyShell Variant Exploited in the Wild
CVE-2022-41040 and CVE-2022-41082: ProxyShell Variant Exploited in the Wild

Published: 2022-09-30

Microsoft has confirmed reports of two zero-day vulnerabilities in Microsoft Exchange Server that have been exploited in the wild. Patches are not yet available.

References

https://github.com/CyprianAtsyor/LetsDefend-CVE-2022-41082-Exploitation-Attempt

https://github.com/pakaremon/CyberAttack_CVE_Microsoft_Exchange_Serve

https://github.com/Phemz0/UDMQueries

https://github.com/Phemz0/SocPrimeAreTrash

https://github.com/balki97/OWASSRF-CVE-2022-41082-POC

https://github.com/balki97/NotProxyShellHunter-CVE-2022-41082-POC

https://github.com/LivingFree8/CVE-2022-41082-RCE-POC

https://github.com/Adynervi/CVE-2022-41082-RCE-PoC

https://github.com/sikkertech/CVE-2022-41082

https://github.com/vib3zz/CVE-2022-41082-RCE-POC

https://github.com/stat1st1c/CVE-2022-41082-RCE-POC

https://github.com/backcr4t/CVE-2022-41082-MASS-RCE

https://github.com/backcr4t/CVE-2022-41082-RCE

https://github.com/backcr4t/CVE-2022-41082-RCE-POC

https://github.com/rjsudlow/proxynotshell-IOC-Checker

https://github.com/gitzero0/ProxyNotShell

https://github.com/b3wT/CVE-2022-41082-MASS-SCANNER

https://github.com/kevibeaumont/CVE-2022-41082-RCE-POC

https://github.com/ZephrFish/NotProxyShellScanner

https://github.com/kevbeaumont/CVE-2022-41082-RCE-POC

https://github.com/kev-beaumont/CVE-2022-41082-RCE-POC

https://github.com/k1vin-beaumont/CVE-2022-41082-RCE-POC

https://github.com/krc0m/CVE-2022-41082

https://github.com/mr-r3b00t/NotProxyShellHunter

https://github.com/Diverto/nse-exchange

https://github.com/spher0X/CVE-2022-41082-RCE

https://github.com/0daylabin/ProxyNotShell

https://github.com/TimWallbey/CVE-2022-41082-RCE

https://github.com/revers0id/CVE-2022-41082-PoC

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-41082

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41082

Details

Source: Mitre, NVD

Published: 2022-10-03

Updated: 2026-06-17

Named Vulnerability: ProxyNotShellKnown Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8

Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.9997