CERT-In Vulnerability Note
CIVN-2022-0371
Multiple Vulnerabilities in Microsoft Exchange Server
Original Issue Date:September 30, 2022
Severity Rating: HIGH
Software Affected
- Microsoft Exchange Server versions 2013, 2016, and 2019.
Overview
Multiple vulnerabilities have been reported in Microsoft Exchange Server, which could allow an attacker to perform remote code execution on the targeted system.
Description
These vulnerabilities exist in Microsoft Exchange Server due to post-authentication flaws. An authenticated attacker could exploit these vulnerabilities by sending a specially-crafted request to the affected system.
Successful exploitation of these vulnerabilities could allow an attacker to perform remote code execution on the targeted system.
Note: These vulnerabilities are being exploited in the wild.
Workaround
A patch for the vulnerabilities is currently not available. As a workaround, apply appropriate mitigations issued by the vendor:
https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
Vendor Information
Microsoft
https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
References
GTSC
https://www.gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html
Bleeping Computer
https://www.bleepingcomputer.com/news/security/new-microsoft-exchange-zero-days-actively-exploited-in-attacks/
CVE Name
CVE-2022-41040
CVE-2022-41082
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|