Lucene search

K
hiveproHive ProHIVEPRO:B4C85BEFF3E49468BE44E35CEC3A7DE6
HistorySep 30, 2022 - 10:21 a.m.

Unpatched zero-day vulnerabilities of Microsoft Exchange Server

2022-09-3010:21:56
Hive Pro
www.hivepro.com
124

0.967 High

EPSS

Percentile

99.7%

Threat Level Vulnerability Report For a detailed threat advisory, download the pdf file here Summary Microsoft Exchange Server has two unpatched zero-day vulnerabilities. One of them is a Server-Side Request Forgery (SSRF) vulnerability(CVE-2022-41040), while the second is a remote code execution (RCE) vulnerability (CVE-2022-41082)in PowerShell. An authenticated attacker can exploit these vulnerabilities together to gain access to a victim's system by chaining them together.