⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply updates per vendor instructions.. Due date: 2023-01-31.

CVE-2022-41080Microsoft Exchange Server 2013 Cumulative Update 23 vulnerability

12 documents9 sources
Severity
9.8CRITICALNVD
CNA8.8VulnCheck8.8
EPSS
93.8%
top 0.14%
CISA KEV
KEVRansomware
Added 2023-01-10
Due 2023-01-31
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedNov 9
KEV addedJan 10
KEV dueJan 31
CISA Required Action: Apply updates per vendor instructions.

Description

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2cwh-g5wf-mfh8: Microsoft Exchange Server Elevation of Privilege Vulnerability2022-11-10
CVEList
Microsoft Exchange Server Elevation of Privilege Vulnerability2022-11-09
VulnCheck
Microsoft Exchange Server Privilege Escalation Vulnerability2022

📋Vendor Advisories

2
CISA
Microsoft Exchange Server Privilege Escalation Vulnerability2023-01-10
Microsoft
Microsoft Exchange Server Elevation of Privilege Vulnerability2022-11-08

🕵️Threat Intelligence

6
Huntress
OWASSRF Explained: Analyzing the Microsoft Exchange RCE Vulnerability | Huntress2022-12-29
Unit42
Threat Brief: OWASSRF Vulnerability Exploitation2022-12-23
Unit42
Threat Brief: OWASSRF Vulnerability Exploitation2022-12-23
Wiz
OWASSRF, a new exploit for Exchange vulnerabilities | Wiz Blog2022-12-22
Wiz
OWASSRF, a new exploit for Exchange vulnerabilities | Wiz Blog2022-12-22
CVE-2022-41080 — Microsoft vulnerability | cvebase