CVE-2022-41040

HIGH(8.8)KEVRansomwareLikely Exploited

Microsoft Exchange Server Server-Side Request Forgery Vulnerability

Description

CVE-2022-41040 is a server-side request forgery (SSRF) vulnerability in Microsoft Exchange Server that allows an authenticated attacker to trigger server-side requests to unintended endpoints. As part of the "ProxyNotShell" attack chain, this vulnerability is combined with CVE-2022-41082 to achieve remote code execution. With an EPSS score of 94.17% (99.91th percentile), CVE-2022-41040 is among the most exploited Exchange vulnerabilities. CISA added it to the KEV catalog on September 30, 2022, and it has been confirmed as used in ransomware campaigns.

KEV Information

Vendor
Microsoft
Product
Exchange Server
Date Added
September 30, 2022
Due Date
October 21, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
microsoftexchange server2013; 2016; 2019

References

Weakness Type

CWE-918: Server-Side Request Forgery (SSRF)

CVE-2022-41040 is a server-side request forgery vulnerability in Microsoft Exchange Server's Autodiscover endpoint. The server fails to properly validate and restrict the targets of internally generated requests, allowing an authenticated attacker to redirect requests to the PowerShell backend and other internal endpoints that should not be directly accessible.

Learn more: CWE-918 — Server-Side Request Forgery (SSRF)

Impact Analysis

CVE-2022-41040 is a critical SSRF vulnerability in Microsoft Exchange Server that, while requiring authentication, serves as the gateway to the devastating ProxyNotShell attack chain. By exploiting this SSRF, attackers can access internal Exchange endpoints that are normally restricted, most critically the PowerShell remoting backend. When combined with CVE-2022-41082, the chain enables remote code execution with SYSTEM privileges. Confidentiality, integrity, and availability are all critically impacted through the chained exploitation. The confirmed ransomware association and the EPSS score of 94.17% make this one of the highest-priority Exchange vulnerabilities for remediation.

Exploit Maturity

CISA confirmed active exploitation of CVE-2022-41040 and added it to the KEV catalog on September 30, 2022, with a remediation deadline of October 21, 2022. The vulnerability is confirmed as used in ransomware campaigns as part of the ProxyNotShell chain with CVE-2022-41082. The EPSS score of 94.17% (99.91th percentile) indicates near-certain exploitation activity. Multiple threat groups, including state-sponsored actors, have actively exploited the ProxyNotShell chain against Exchange servers worldwide.

Remediation

  1. Apply Microsoft security updates: Install the November 2022 Exchange Server security updates (KB5019758) that address both CVE-2022-41040 and CVE-2022-41082.
  2. Implement URL Rewrite mitigation: Apply the Microsoft-recommended URL Rewrite rule to block exploitation attempts via the Autodiscover endpoint.
  3. Restrict Autodiscover access: Limit external access to the Exchange Autodiscover endpoint using firewall rules or reverse proxy configurations.
  4. Monitor Exchange logs: Review IIS logs for suspicious patterns targeting the Autodiscover endpoint with encoded URL patterns typical of SSRF exploitation.
  5. Assess Exchange deployment model: Evaluate whether hybrid or cloud-only Exchange deployments could reduce the on-premises attack surface.

Technical Details

CVE-2022-41040 exploits the Autodiscover endpoint in Microsoft Exchange Server to perform server-side request forgery. The vulnerability exists in how Exchange handles URL normalization in the Autodiscover front-end proxy. An authenticated attacker can craft requests that bypass the URL path validation, causing the Exchange front-end to proxy the request to unintended backend services, particularly the PowerShell remoting endpoint. This SSRF is functionally similar to the ProxyShell SSRF (CVE-2021-34473) but uses a different bypass technique. The authenticated nature means the attacker needs valid Exchange credentials, but these are often obtained through phishing, credential stuffing, or prior breaches. The SSRF component alone does not achieve code execution but is the critical enabler for CVE-2022-41082.

Frequently Asked Questions

Is CVE-2022-41040 being actively exploited?

Yes, CVE-2022-41040 is actively exploited as part of the ProxyNotShell chain and is confirmed in ransomware campaigns. CISA added it to the KEV catalog on September 30, 2022, and the EPSS score of 94.17% confirms near-certain exploitation.

What products are affected by CVE-2022-41040?

CVE-2022-41040 affects Microsoft Exchange Server 2013, 2016, and 2019 with on-premises deployments. Exchange Online is not affected.

How do I fix CVE-2022-41040?

Apply the November 2022 Exchange Server security updates. As a temporary mitigation, implement the URL Rewrite rule recommended by Microsoft to block the SSRF exploit path.

How severe is CVE-2022-41040?

CVE-2022-41040 is a critical SSRF vulnerability with an EPSS score of 94.17% (99.91th percentile) and confirmed ransomware usage. As part of the ProxyNotShell chain with CVE-2022-41082, it enables remote code execution on Exchange Server.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score99.96%
EPSS Percentile100.0%

Dates

PublishedOctober 3, 2022
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.