Vulnerability record · CVE-2022-41040 · published 3 October 2022
CVE-2022-41040: Microsoft Exchange Server SSRF elevation of privilege
Microsoft · Exchange Server
CVE-2022-41040 is a server-side request forgery (SSRF) flaw in Microsoft Exchange Server that allows an authenticated attacker to escalate privileges. It is one of the two ProxyNotShell vulnerabilities and was exploited in the wild, including by the Play ransomware group. The record gives only a one-line description, so the exact vulnerable code path and affected builds are not specified here.
Description
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with confirmed ransomware use, near-maximum EPSS, and a public exploit, so active exploitation is expected.
What it is
CVE-2022-41040 is a server-side request forgery (SSRF) flaw in Microsoft Exchange Server that allows an authenticated attacker to escalate privileges. It is one of the two ProxyNotShell vulnerabilities and was exploited in the wild, including by the Play ransomware group. The record gives only a one-line description, so the exact vulnerable code path and affected builds are not specified here.
Impact
An attacker with a low-privileged Exchange account can leverage SSRF to reach internal services and escalate to higher privileges, with high impact to confidentiality, integrity and availability. In observed campaigns this chained into remote code execution and ransomware deployment.
Attack surface
Reachable over the network via the Exchange web interface (AV:N) with low privileges required (PR:L) and no user interaction (UI:N). No public-facing authentication bypass is described in this record; the attacker needs valid credentials.
Exploitation
Listed in CISA KEV (added 2022-09-30) with known ransomware campaign use, and EPSS probability is 0.99956 (99.97th percentile). A public exploit reference exists (Packet Storm, ProxyNotShell RCE), so exploitation is confirmed and widespread.
What to do
- Apply the Microsoft Exchange security updates referenced in the MSRC advisory for CVE-2022-41040 as the first action.
- If patching cannot be done immediately, apply the vendor mitigation (URL rewrite rule blocking the known attack pattern) and restrict external access to Exchange.
- Enforce MFA and least privilege on Exchange accounts to reduce the value of a single low-privileged credential.
- Monitor and limit outbound traffic from Exchange servers to internal services to blunt SSRF reach.
- Review the CISA KEV required action and confirm remediation by the listed due date.
Detection
- Hunt Exchange IIS logs for requests matching the ProxyNotShell SSRF pattern (autodiscover/autodiscover.json with crafted email parameters).
- Alert on Exchange server processes making unexpected outbound or loopback HTTP requests to internal hosts.
- Monitor for post-exploitation behavior tied to Play ransomware, such as suspicious child processes from w3wp.exe.
- Correlate authentication events for low-privileged Exchange accounts with subsequent privileged operations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-41040 to the Known Exploited Vulnerabilities catalog on 30 September 2022 as "Microsoft Exchange Server Server-Side Request Forgery Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 21 October 2022.
Ransomware crews whose documented playbooks reference this CVE: