CVE-2022-41040 is an authenticated server-side request forgery and elevation-of-privilege vulnerability affecting on-premises Microsoft Exchange Server 2013, 2016, and 2019. Insufficient input filtering in the Exchange Autodiscover mechanism allows an attacker with valid Exchange credentials to reach the privileged Exchange PowerShell endpoint. It forms the first stage of ProxyNotShell, which chains this vulnerability with CVE-2022-41082 to achieve remote code execution through PowerShell remoting. The chain has been actively exploited. Exchange Online is unaffected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit module: 'exchange_proxynotshell_rce.rb', which exploits the ProxyNotShell vulnerabilities (CVE-2022-41040 and CVE-2022-41082) in Microsoft Exchange Server 2019. The exploit chains an SSRF (Server-Side Request Forgery) and a deserialization flaw to achieve remote code execution on the target Exchange server. The attacker must have valid credentials to authenticate. The module supports two payload types: direct command execution and Windows executable dropper. The exploit interacts with Exchange's HTTP endpoints, specifically '/mapi/nspi/' for version checking and '/Autodiscover/autodiscover.json' for the SSRF and PowerShell backend access. The code is operational and leverages Metasploit's payload system, allowing for customizable payloads. The repository is structured as a typical Metasploit exploit module, with all logic contained in a single Ruby file.
This repository provides a proof-of-concept (POC) exploit for CVE-2022-41040, a Server Side Request Forgery (SSRF) vulnerability in Microsoft Exchange Server. The repository contains two files: a Python script (CVE-2022-41040.py) and a README.md. The Python script automates the process of downloading SSRF payload templates, replacing a placeholder with an attacker-supplied OOB domain, and generating a list of formatted payloads for mass testing using ffuf and unfurl. The README.md explains both manual and automated exploitation steps, provides example payloads, and lists required tools. The exploit's main capability is to trigger SSRF requests from Exchange servers to an attacker-controlled domain, allowing the attacker to confirm the vulnerability via OOB interactions. The repository is structured for both manual and automated mass exploitation, targeting the /autodiscover/autodiscover.json endpoint on Exchange servers. No weaponized or post-exploitation payloads are included; the focus is on vulnerability verification.
This repository contains a Python proof-of-concept exploit for CVE-2022-41040, a server-side request forgery (SSRF) vulnerability in Microsoft Exchange Server. The repository consists of a README with usage instructions and a single Python script, 'microsoft_exchange_server_proxynotshell_ssrf.py'. The script is designed to be used as a custom module in Metasploit but is written in standalone Python, not Ruby. It requires the 'requests' library and interacts with the target Exchange server by sending crafted HTTP requests to the '/autodiscover/autodiscover.json' endpoint, attempting to trigger SSRF. The exploit uses the public DNSLog service (dnslog.cn) to detect if the Exchange server makes outbound DNS requests, confirming the SSRF vulnerability. The script also attempts to extract additional information from the Exchange server via the '/mapi/nspi' endpoint. The exploit requires valid authentication to the Exchange server and is intended for security testing and vulnerability confirmation. No weaponized or post-exploitation payload is included; the script is a POC for detection and confirmation of the SSRF flaw.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
One component of an authenticated Exchange Server exploit chain enabling server-side request forgery and remote code execution. Discussed as a historical comparison.
CVE-2022-41040 is the specific vulnerability referenced in a GitHub conversation about adding a detection template.
An authenticated server-side request forgery vulnerability affecting on-premises Microsoft Exchange servers. Attackers can chain it with CVE-2022-41082 to execute code remotely. The report describes limited, targeted exploitation first observed in August 2022. Its exposure scans and network-flow findings identify potentially affected systems but do not establish that every observed system was compromised.
A Microsoft Exchange exploit chain comprising CVE-2022-41040 and CVE-2022-41082, used to gain unauthenticated remote code execution on unpatched Exchange servers for initial access.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.