CVE-2022-41040
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
14 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.22%
probability
This CVE has a 94.22% probability
of being exploited in the next 30 days.
0%
Top 99.9th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroServer-side request forgery
Attack Intelligence
Google Project Zero
Patched
Nov. 8, 2022
Reported by
DA-0x43-Dx4-DA-Hx2-Tx2-TP-S-Q from GTSC working with Trend Micro Zero Day Initiative
Root Cause Analysis
???
Exploits & PoC
kljunowsky/CVE-2022-41040-POC
CVE-2022-41040 - Server Side Request Forgery (SSRF) in Microsoft Exchange Server
91
TaroballzChen/CVE-2022-41040-metasploit-ProxyNotShell
the metasploit script(POC) about CVE-2022-41040. Microsoft Exchange are vulnerable to a server-side request forgery (SSRF) attack. An authenticated at
35
r3dcl1ff/CVE-2022-41040
mitigation script for MS Exchange server vuln
5
d3duct1v/CVE-2022-41040
Code set relating to CVE-2022-41040
5
rjsudlow/proxynotshell-IOC-Checker
Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)
5
ITPATJIDR/CVE-2022-41040
PoC CVE-2022-41040 — ITPATJIDR/CVE-2022-41040
1
0-Gram/CVE-2022-41040
PoC CVE-2022-41040 — 0-Gram/CVE-2022-41040
0
CentarisCyber/CVE-2022-41040_Mitigation
PoC CVE-2022-41040 — CentarisCyber/CVE-2022-41040_Mitigation
0
8 repos — triés par ⭐
Rechercher sur GitHub ↗
Microsoft confirms new Exchange zero-days are used in attacks
BleepingComputer
Sep 30, 2022
Microsoft fixes ProxyNotShell Exchange zero-days exploited in attacks
BleepingComputer
Nov 08, 2022
November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years).
Qualys
Nov 08, 2022
Defense Lessons From the Black Basta Ransomware Playbook
Qualys
Feb 25, 2025
Security Advisory 2022-079
CERT-EU
Nov 09, 2022
Microsoft Exchange servers hacked to deploy LockBit ransomware
BleepingComputer
Oct 11, 2022
Fake Microsoft Exchange ProxyNotShell exploits for sale on GitHub
BleepingComputer
Oct 03, 2022
Qualys Research Team: Threat Thursdays, October 2022
Qualys
Oct 28, 2022
Qualys Response to ProxyNotShell Microsoft Exchange Server Zero-Day Threat Using Qualys Cloud Platform
Qualys
Sep 30, 2022
Microsoft updates mitigation for ProxyNotShell Exchange zero days
BleepingComputer
Oct 05, 2022
Microsoft Exchange server zero-day mitigation can be bypassed
BleepingComputer
Oct 03, 2022
Signal Intelligence
Confidence
82%
EPSS
94.22%
Mentions
14
Last Seen
Feb 25, 2025
CNA Information
Analyst Note
CVE-2022-41040 is confirmed as an elevation of privilege vulnerability in Microsoft Exchange Server with a high CVSS score of 8.8, inclusion in Google Project Zero research, and documentation in CERT-EU security advisories indicating active exploitation. The evidence strongly supports the confirmed status, though the single article and absence from CISA KEV list warrant a slightly conservative confidence level.
Threat Actors 16
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
Cobalt
apt_group
Financial crime
🇷🇺 RU
Harvester
apt_group
Information theft and espionage
Unknown
Hacking Team
apt_group
🇮🇹 IT
Kinsing
apt_group
🇷🇺 RU
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Andariel Group
apt_group
🇰🇷 KR
TeamTNT
apt_group
🇩🇪 DE
APT-C-36
apt_group
Information theft and espionage
🇨🇴 CO
Roaming Mantis
apt_group
🇯🇵 JP
Rocke
apt_group
🇨🇳 CN
SEXi
apt_group
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Operation Shadow Force
apt_group
🇨🇳 CN
Operation Black Atlas
apt_group
Financial crime
Triage Info
Decided atMar 03, 2026