← Vulnerability feed

Vulnerability record · CVE-2022-41040 · published 3 October 2022

CVE-2022-41040: Microsoft Exchange Server SSRF elevation of privilege

Microsoft · Exchange Server

CVE-2022-41040 is a server-side request forgery (SSRF) flaw in Microsoft Exchange Server that allows an authenticated attacker to escalate privileges. It is one of the two ProxyNotShell vulnerabilities and was exploited in the wild, including by the Play ransomware group. The record gives only a one-line description, so the exact vulnerable code path and affected builds are not specified here.

8.8 CVSS 3.1 High CISA KEV since 30 Sep 2022 Known ransomware use EPSS 100% · top 0.1% CWE-918 · Server-side request forgery (SSRF)
8.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
6References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: medium.

critical priorityIt is in CISA KEV with confirmed ransomware use, near-maximum EPSS, and a public exploit, so active exploitation is expected.

What it is

CVE-2022-41040 is a server-side request forgery (SSRF) flaw in Microsoft Exchange Server that allows an authenticated attacker to escalate privileges. It is one of the two ProxyNotShell vulnerabilities and was exploited in the wild, including by the Play ransomware group. The record gives only a one-line description, so the exact vulnerable code path and affected builds are not specified here.

Impact

An attacker with a low-privileged Exchange account can leverage SSRF to reach internal services and escalate to higher privileges, with high impact to confidentiality, integrity and availability. In observed campaigns this chained into remote code execution and ransomware deployment.

Attack surface

Reachable over the network via the Exchange web interface (AV:N) with low privileges required (PR:L) and no user interaction (UI:N). No public-facing authentication bypass is described in this record; the attacker needs valid credentials.

Exploitation

Listed in CISA KEV (added 2022-09-30) with known ransomware campaign use, and EPSS probability is 0.99956 (99.97th percentile). A public exploit reference exists (Packet Storm, ProxyNotShell RCE), so exploitation is confirmed and widespread.

What to do

  • Apply the Microsoft Exchange security updates referenced in the MSRC advisory for CVE-2022-41040 as the first action.
  • If patching cannot be done immediately, apply the vendor mitigation (URL rewrite rule blocking the known attack pattern) and restrict external access to Exchange.
  • Enforce MFA and least privilege on Exchange accounts to reduce the value of a single low-privileged credential.
  • Monitor and limit outbound traffic from Exchange servers to internal services to blunt SSRF reach.
  • Review the CISA KEV required action and confirm remediation by the listed due date.

Detection

  • Hunt Exchange IIS logs for requests matching the ProxyNotShell SSRF pattern (autodiscover/autodiscover.json with crafted email parameters).
  • Alert on Exchange server processes making unexpected outbound or loopback HTTP requests to internal hosts.
  • Monitor for post-exploitation behavior tied to Play ransomware, such as suspicious child processes from w3wp.exe.
  • Correlate authentication events for low-privileged Exchange accounts with subsequent privileged operations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-41040 to the Known Exploited Vulnerabilities catalog on 30 September 2022 as "Microsoft Exchange Server Server-Side Request Forgery Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 21 October 2022.

Ransomware crews whose documented playbooks reference this CVE: