Microsoft warned that attackers were actively exploiting a zero-day chain in on-premises Microsoft Exchange Server, later tracked as ProxyNotShell and assigned CVE-2022-41040 and CVE-2022-41082. The flaws affected Exchange Server 2013, 2016, and 2019, while Exchange Online was not affected. The attack chain used a server-side request forgery (SSRF) bug to reach PowerShell remoting and achieve remote code execution, and reports indicated the activity required valid email credentials from a non-admin user.
Microsoft and security researchers urged organizations to apply interim protections immediately, including an IIS URL Rewrite rule to block known exploit paths and restricting or disabling Remote PowerShell where possible. Guidance also highlighted the need to review IIS logs and related telemetry for signs of compromise, as the campaign was reportedly already being used in real-world attacks and drew comparisons to the earlier ProxyShell exploitation wave.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft Security Response Center published customer guidance for the reported Exchange zero-days, assigning CVE-2022-41040 and CVE-2022-41082. Microsoft said Exchange Online was not affected and recommended temporary mitigations including an IIS URL Rewrite rule and restricting Remote PowerShell where possible.
Public discussion of the Exchange zero-day campaign began on September 29, 2022, including a GTSC blog post warning of active exploitation. The campaign involved a new attack chain against Microsoft Exchange Server.
The Exchange vulnerabilities later dubbed ProxyNotShell were reported as having been actively exploited in the wild for at least a month before public disclosure. The chain affected on-premises Exchange Server 2013, 2016, and 2019 and required valid credentials.
GTSC reported the Microsoft Exchange vulnerabilities to Microsoft through the Zero Day Initiative. A later reference states this report was made 22 days before public discussion began.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.