Attackers actively exploited the Microsoft Exchange Server vulnerabilities CVE-2022-41040 and CVE-2022-41082, widely known as ProxyNotShell, to gain remote code execution on vulnerable on-premises deployments. Microsoft disclosed the attacks and analyzed the exploit chain, which abuses the two flaws together, while affected products included supported Exchange Server 2013, 2016, and 2019 cumulative update versions; Exchange Online was not affected.
Security monitoring in the weeks after disclosure showed sustained scanning and exploitation attempts, with one SOC reporting activity beginning on October 3 and continuing intermittently through November, and more than 90% of observed source countries tied to the United States. Many requests appeared to use the ZGrab scanning tool based on User-Agent headers, and public proof-of-concept code increased the likelihood of continued abuse. Microsoft released patches for affected Exchange versions, and organizations running on-premises Exchange were urged to apply the vendor fixes without delay.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC reported increased attack activity during November 2022 targeting the Exchange vulnerabilities CVE-2022-41040 and CVE-2022-41082. It said detections continued intermittently after the initial October observations, with more than 90% of observed source countries identified as the United States.
MBSD-SOC reported first observing attacks targeting CVE-2022-41040 and CVE-2022-41082 on October 3, 2022. The observed requests targeted Exchange autodiscover paths and many appeared to use the ZGrab scanning tool.
Microsoft publicly disclosed CVE-2022-41040 and CVE-2022-41082 affecting on-premises Microsoft Exchange Server. The chained vulnerabilities, later widely referred to as ProxyNotShell, can enable remote code execution.
Microsoft released remediated versions for affected Exchange Server 2013, 2016, and 2019 cumulative update branches. The fixes addressed the on-premises products listed as affected, while Exchange Online was noted as unaffected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
mbsd.jp
Open sourcemicrosoft.com
Open sourcemsrc-blog.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.