Microsoft Exchange Server Elevation of Privilege Vulnerability
Published: 2022-09-30
Microsoft has confirmed reports of two zero-day vulnerabilities in Microsoft Exchange Server that have been exploited in the wild. Patches are not yet available.
https://www.kb.cert.org/vuls/id/915563
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41040
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-352a
https://www.mandiant.com/resources/blog/zero-days-exploited-2022
https://www.tenable.com/cyber-exposure/tenable-2022-threat-landscape-report
Published: 2022-10-03
Updated: 2025-02-24
Named Vulnerability: ProxyNotShellKnown Exploited Vulnerability (KEV)
Base Score: 9
Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C
Severity: High
Base Score: 8.8
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.94229