Researchers identified OWASSRF, an in-the-wild exploit chain targeting on-premises Microsoft Exchange Server through Outlook Web Access (OWA). The technique combines CVE-2022-41080 and CVE-2022-41082 to obtain remote code execution and bypasses URL-rewrite mitigations deployed against the earlier ProxyNotShell exploitation path involving CVE-2022-41040 and CVE-2022-41082.
The Play ransomware group was observed using OWASSRF against organizations, with victims concentrated in Latin America and particularly Brazil. Exchange Server 2013, 2016, and 2019 installations that remain unpatched are affected; Microsoft’s KB5019758 security update, or a later update, remediates the exposure. Organizations unable to patch immediately should disable OWA and limit Remote PowerShell and externally accessible Exchange services.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers detected in-the-wild OWASSRF exploitation, in which the Play ransomware group chained CVE-2022-41080 and CVE-2022-41082 through Outlook Web Access to bypass ProxyNotShell URL-rewrite mitigations and execute code. The activity primarily targeted Latin American organizations, particularly in Brazil.
Microsoft released November 2022 Patch Tuesday updates, including KB5019758 for Exchange Server 2013, 2016, and 2019. The update addressed CVE-2022-41040, CVE-2022-41080, and CVE-2022-41082.
Exploitation of the ProxyNotShell Exchange vulnerability chain, involving CVE-2022-41040 and CVE-2022-41082, was reported in the wild. CVE-2022-41040 is an SSRF vulnerability and CVE-2022-41082 permits remote code execution on affected Exchange servers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.