CVE-2022-41040

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 14 articles

EPSS Score

Source: FIRST.org · 2026-05-24
94.22%
probability
This CVE has a 94.22% probability of being exploited in the next 30 days.
0% Top 99.9th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Server-side request forgery

Attack Intelligence

Google Project Zero

Patched
Nov. 8, 2022
Reported by
DA-0x43-Dx4-DA-Hx2-Tx2-TP-S-Q from GTSC working with Trend Micro Zero Day Initiative
Root Cause Analysis
???

Exploits & PoC

kljunowsky/CVE-2022-41040-POC

CVE-2022-41040 - Server Side Request Forgery (SSRF) in Microsoft Exchange Server

91
TaroballzChen/CVE-2022-41040-metasploit-ProxyNotShell

the metasploit script(POC) about CVE-2022-41040. Microsoft Exchange are vulnerable to a server-side request forgery (SSRF) attack. An authenticated at

35
r3dcl1ff/CVE-2022-41040

mitigation script for MS Exchange server vuln

5
d3duct1v/CVE-2022-41040

Code set relating to CVE-2022-41040

5
rjsudlow/proxynotshell-IOC-Checker

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

5
ITPATJIDR/CVE-2022-41040

PoC CVE-2022-41040 — ITPATJIDR/CVE-2022-41040

1
0-Gram/CVE-2022-41040

PoC CVE-2022-41040 — 0-Gram/CVE-2022-41040

0
CentarisCyber/CVE-2022-41040_Mitigation

PoC CVE-2022-41040 — CentarisCyber/CVE-2022-41040_Mitigation

0
8 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
82%
EPSS 94.22%
Mentions 14
Last Seen Feb 25, 2025

CNA Information

Analyst Note

CVE-2022-41040 is confirmed as an elevation of privilege vulnerability in Microsoft Exchange Server with a high CVSS score of 8.8, inclusion in Google Project Zero research, and documentation in CERT-EU security advisories indicating active exploitation. The evidence strongly supports the confirmed status, though the single article and absence from CISA KEV list warrant a slightly conservative confidence level.

Threat Actors 16

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Cobalt
apt_group Financial crime 🇷🇺 RU
Harvester
apt_group Information theft and espionage Unknown
Hacking Team
apt_group 🇮🇹 IT
Kinsing
apt_group 🇷🇺 RU
Infy
apt_group Information theft and espionage 🇮🇷 IR
Andariel Group
apt_group 🇰🇷 KR
TeamTNT
apt_group 🇩🇪 DE
APT-C-36
apt_group Information theft and espionage 🇨🇴 CO
Roaming Mantis
apt_group 🇯🇵 JP
Rocke
apt_group 🇨🇳 CN
SEXi
apt_group
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Operation Shadow Force
apt_group 🇨🇳 CN
Operation Black Atlas
apt_group Financial crime

Triage Info

Decided atMar 03, 2026