CVE-2022-41080

HIGH(8.8)KEVRansomwareLikely Exploited

Microsoft Exchange Server Privilege Escalation Vulnerability

Description

CVE-2022-41080 is a high-severity elevation of privilege vulnerability in Microsoft Exchange Server. This flaw allows an authenticated attacker with low-level credentials to escalate their privileges on the Exchange Server, potentially gaining administrative control over the mail system. The vulnerability is remotely exploitable over the network with low attack complexity and requires no user interaction, making it straightforward to abuse once an attacker has obtained basic authentication credentials. CISA has confirmed active exploitation of CVE-2022-41080 in the wild and has flagged it as used in ransomware campaigns. With an EPSS score of 93.8% (99.85th percentile), this Exchange Server vulnerability represents a critical threat to organizations running unpatched installations.

KEV Information

Vendor
Microsoft
Product
Exchange Server
Date Added
January 10, 2023
Due Date
January 31, 2023
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

Affected Products

VendorProductVersion
microsoftexchange server2013; 2016; 2019

Multiple CVSS Assessments

Source: [email protected](Secondary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: [email protected](Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

No CWE Assigned

No specific CWE (Common Weakness Enumeration) has been assigned to CVE-2022-41080 by NVD. The vulnerability is classified as an elevation of privilege flaw in Microsoft Exchange Server, indicating that it allows attackers to gain higher access levels than their authenticated credentials would normally permit. Without a formal CWE mapping, the exact underlying weakness pattern has not been categorized, but the behavior is consistent with improper privilege management or access control deficiencies.

Impact Analysis

CVE-2022-41080 carries a CVSS v3.1 score of 8.8 (High), reflecting its significant exploitability and impact. The vulnerability is remotely exploitable over the network (AV:N) without physical access requirements. Attack complexity is low (AC:L), meaning exploitation is straightforward with no special preconditions. While low-level privileges are required (PR:L), meaning the attacker must have authenticated access to Exchange, no user interaction is needed (UI:N), allowing silent exploitation. All three impact categories — confidentiality, integrity, and availability — are rated high (C:H/I:H/A:H), indicating that successful exploitation can lead to complete compromise of the Exchange Server, including access to all mailbox contents, ability to modify configurations, and disruption of mail services. The EPSS score of 93.8% signals near-certain exploitation activity. Critically, CISA has flagged this vulnerability as known to be used in ransomware campaigns, significantly elevating the risk for affected organizations.

Exploit Maturity

CVE-2022-41080 has been confirmed as actively exploited in the wild by CISA, which added it to the Known Exploited Vulnerabilities catalog with a remediation deadline of January 31, 2023. Notably, CISA has identified this vulnerability as being used in ransomware operations, indicating that threat actors are leveraging it as part of organized attack campaigns targeting Exchange Server environments. The EPSS score of 93.8% (99.85th percentile) corroborates the high likelihood of ongoing exploitation. While no public exploit code tagged as such appears in the NVD references, the ransomware association and confirmed active exploitation indicate that weaponized exploits are circulating among threat actors. Microsoft has published a security advisory and patches through the Microsoft Security Response Center.

Remediation

  1. Apply Microsoft security updates immediately. Install the patches provided through Microsoft's Security Update Guide for CVE-2022-41080. The KEV required action states: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
  2. Verify Exchange Server patch level. Confirm that all Exchange Server instances in your environment have been updated to the latest cumulative and security updates from Microsoft. Check the specific Exchange Server version you are running against Microsoft's advisory for applicable patches.
  3. Restrict Exchange Server network exposure. Limit access to Exchange administrative interfaces to trusted internal networks only. Deploy network segmentation to isolate Exchange Servers from general user networks and ensure management ports are not accessible from the internet.
  4. Monitor for indicators of compromise. Review Exchange Server logs for signs of privilege escalation, unusual administrative actions, or unauthorized mailbox access. Check for indicators associated with ransomware activity, such as unexpected service accounts, lateral movement patterns, or encryption of files.
  5. Enforce least-privilege access and MFA. Since the vulnerability requires low-level authenticated access, implement multi-factor authentication for all Exchange accounts and enforce the principle of least privilege to minimize the impact of compromised credentials.

Technical Details

CVE-2022-41080 is an elevation of privilege vulnerability in Microsoft Exchange Server that allows an authenticated user with low privileges to escalate to higher access levels. The network-based attack vector (AV:N) means exploitation can be performed remotely against any reachable Exchange Server instance. Low attack complexity (AC:L) indicates that the exploit does not require winning a race condition or overcoming other variable obstacles. The requirement for low privileges (PR:L) means the attacker needs a valid Exchange account, but only basic user-level authentication is sufficient to trigger the vulnerability. The scope remains unchanged (S:U), meaning the privilege escalation occurs within the Exchange Server context itself, but with high impact across confidentiality, integrity, and availability (C:H/I:H/A:H), a successful attack effectively grants full control over the Exchange environment. No specific CWE has been assigned, but the vulnerability pattern is consistent with improper access control enforcement during privilege operations within the Exchange request handling pipeline.

Frequently Asked Questions

Is CVE-2022-41080 being actively exploited?

Yes, CVE-2022-41080 is actively exploited in the wild. CISA has added it to the Known Exploited Vulnerabilities catalog with a remediation deadline of January 31, 2023. Furthermore, CISA has confirmed that this vulnerability is being used in ransomware campaigns, making it a high-priority patching target for all organizations running Microsoft Exchange Server.

What products are affected by CVE-2022-41080?

CVE-2022-41080 affects Microsoft Exchange Server. Microsoft has published specific patch guidance through the Security Update Guide. Organizations should check their Exchange Server version against the advisory to determine which cumulative updates and security patches are required.

How do I fix CVE-2022-41080?

Apply the security updates from Microsoft's Security Update Guide for CVE-2022-41080 immediately. Additionally, restrict network access to Exchange administrative interfaces, implement multi-factor authentication for all Exchange accounts, and monitor logs for signs of privilege escalation or ransomware activity. See the Remediation section for detailed steps.

How severe is CVE-2022-41080?

CVE-2022-41080 is rated High severity with a CVSS v3.1 score of 8.8 out of 10. Although it requires low-level authenticated access, it can be exploited remotely with low complexity and no user interaction. Its confirmed use in ransomware campaigns and an EPSS score in the 99.85th percentile make it an exceptionally dangerous vulnerability.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score77.33%
EPSS Percentile99.5%

Dates

PublishedNovember 9, 2022
Last ModifiedAugust 10, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.