/?pid=microsoft-issues-advisory-about-two-0-day-vulnerabilities-in-exchange-23562

Updated:12:54 PM EST Dec 22


this is ggmania.com subsite Microsoft issues advisory about two 0-day vulnerabilities in Exchange - TechAmok

Microsoft issues advisory about two 0-day vulnerabilities in Exchange - [security]
10:31 AM EDT - Sep,30 2022 - post a comment

Microsoft Exchange Server just can't seem to catch a break. Last year, the company warned about widespread attacks on on-premises servers and rushed to detail mitigations and release security updates within weeks. Now, it seems that the software is once again under attack via two 0-day vulnerabilities. As is usually the case, Exchange Online customers are not affected and don't need to do anything. The vulnerabilities apply to on-premises installations of Exchange Server 2013, 2016, and 2019. The two vulnerabilities are tagged CVE-2022-41040 and CVE-2022-41082, respectively. The former is a Server-Side Request Forgery (SSRF) vulnerability while the latter enables a malicious actor to carry out remote code execution (RCE) attacks via PowerShell. That said, an attacker would need authenticated access to Exchange Server to leverage either of the two vulnerabilities. Since there is no patch available yet, Microsoft understandably hasn't gone into the details of the attack chain. That said, it has noted a couple of mitigations which involve adding a blocking rule in URL Rewrite Instructions and blocking ports 5985 (HTTP) and 5986 (HTTPS) which are utilized by Remote PowerShell. Unfortunately, there are no specific hunting queries available for Microsoft Sentinel and Microsoft Defender for Endpoint can only detect post-exploitation activities, which also includes the detection of the "Chopper" web shell malware that has been spotted in in-the-wild attacks. Microsoft has assured customers that it is working on an "accelerated timeline" for a fix, but has not disclosed a tentative patch release date as of yet. You can find more details about mitigations and detections for the 0-day vulnerabilities here.

Short overview of recent news articles

NVIDIA Killing Cheap 16GB Local AI GPUs? (Dec,22 2025 )

Top 10 Movie Sequels of All Time (Dec,21 2025 )

He Built a Privacy Tool. Now He's Going to Prison (Kone Rodriguez, (Dec,21 2025 )

Insane Moves! B-Boy Shigekix vs. B-Boy Issin - Red Bull BC One World (Dec,20 2025 )

9800X3D & RTX 5070 Ti Gaming PC - MSI Project Zero Done Right (Dec,20 2025 )

The XG27AQWMG Sets a New Standard for 1440p OLED (Dec,19 2025 )

OnePlus 15R Boasts Huge 7,400 mAh Battery (Dec,19 2025 )

Motorola Refreshes moto g power for 2026 (Dec,19 2025 )

NVIDIA GeForce 591.59 WHQL Driver (Dec,18 2025 )

Are We Quitting YouTube Due To DRAM Apocalypse? (Dec,18 2025 )

The Samsung TriFold is AWESOME! (Dec,16 2025 )

$30 vs $30,000 TV (Dec,16 2025 )

Stranger Things 5 - Volume 2 Trailer (Dec,16 2025 )

Google Brings Live Video Sharing to 911 Calls on Android (Dec,14 2025 )

Samsung One UI 8.5 Will Offer New Features (Dec,14 2025 )

Dell AW3225QF Review - 32-inch curved gaming monitor (Dec,14 2025 )

HW News - AMD Says AI Definitely, Absolutely Not A Bubble, New (Dec,13 2025 )

The BEST Smartphones of 2025! (Dec,13 2025 )

10 Atmospheric Games That Might CHANGE YOUR LIFE (Dec,11 2025 )

Samsung Galaxy S26 Ultra - Samsung Isn't Hiding It Anymore (Dec,11 2025 )

AMD Releases Adrenalin Edition 25.12.1 WHQL Drivers (Dec,10 2025 )

S25 Ultra VS 17 Pro Max (Dec,10 2025 )

All You Need Is Kill - Official Trailer (Dec,09 2025 )

Why can’t you be NORMAL?!? Roasting Staff Setups (Dec,09 2025 )

A Ryzen Cooling MONSTER - be quiet Silent Loop 3 Review (Dec,09 2025 )

The Boys - Official Final Season Trailer (Dec,07 2025 )

Unemployed in your 30's (Dec,06 2025 )

Play Store Customers to Receive Automatic Payments from $700 Million (Dec,05 2025 )

Google's Second Release of Android 16 Brings Smart Notifications (Dec,05 2025 )

Netflix To Buy Warner Bros for $82.7 Billion (Dec,05 2025 )

Micron to Exit Crucial Consumer Business, Ending Retail SSD and DRAM (Dec,03 2025 )

Samsung Galaxy Z TriFold Unboxing! (Dec,02 2025 )

Top 5 Best CPUs of 2025 (Nov,30 2025 )

Google Adding AirDrop to Android (Nov,30 2025 )

20 TOP ALIEXPRESS products for BLACK FRIDAY (Nov,29 2025 )

Stop Wasting Money on Premium Monitors (Nov,26 2025 )

The Blackest Friday - Tech News Nov 23 (Nov,23 2025 )

T-Roc: Will this new VW be the best car of 2026? (Nov,23 2025 )

Can I build my own Steam Machine? (Nov,23 2025 )

50 NEXT-LEVEL Gadgets Every Man NEEDS to See (Nov,22 2025 )

RETURN TO SILENT HILL Trailer (2026) (Nov,22 2025 )

I was WRONG about the Porsche 911 GT3 (or was I?) (Nov,20 2025 )

Pi GPT Tool Turns Raspberry Pi into a ChatGPT-Powered Smart Device (Nov,20 2025 )

Rainbow Six Siege X - Official 'Team Rainbow's Last Mission' (Nov,17 2025 )

Stranger Things Seasons 1-4 Recap (Nov,17 2025 )

Kill Bill: The Whole Bloody Affair - Official Trailer (2025) Uma (Nov,16 2025 )

The Devil Wears Prada 2 - Official Teaser Trailer (2026) Meryl (Nov,15 2025 )

Valve’s New Console and Controller - STEAM Machine & STEAM (Nov,15 2025 )

Valve Steam Machine, Desktop SteamOS, Steam Frame VR, & Controller | (Nov,15 2025 )

Battlefield REDSEC - Official Live-Action Trailer (Nov,01 2025 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs