CVE-2022-41082

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 14 articles

EPSS Score

Source: FIRST.org · 2026-05-24
91.51%
probability
This CVE has a 91.51% probability of being exploited in the next 30 days.
0% Top 99.7th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Remote code execution

Attack Intelligence

Google Project Zero

Patched
Nov. 8, 2022
Reported by
Piotr Bazydlo (@chudypb) and DA-0x43-Dx4-DA-Hx2-Tx2-TP-S-Q from GTSC working with Trend Micro Zero Day Initiative
Root Cause Analysis
???

Exploits & PoC

balki97/OWASSRF-CVE-2022-41082-POC

PoC for the CVE-2022-41080 , CVE-2022-41082 and CVE-2022-41076 Vulnerabilities Affecting Microsoft Exchange Servers

93
soltanali0/CVE-2022-41082

CVE-2022-41082-poc

3
bigherocenter/CVE-2022-41082-POC

PoC CVE-2022-41082 — bigherocenter/CVE-2022-41082-POC

1
3 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
85%
EPSS 91.51%
Mentions 14
Last Seen Feb 25, 2025

CNA Information

Analyst Note

This CVE is confirmed as an exploited zero-day affecting Microsoft Exchange Server with a high CVSS score of 8.0 and inclusion in Google Project Zero, demonstrating active weaponization in the wild. The CERT-EU security advisory corroborates the vulnerability's severity and real-world exploitation, though limited article coverage prevents a higher confidence score.

Threat Actors 18

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Cobalt
apt_group Financial crime 🇷🇺 RU
Harvester
apt_group Information theft and espionage Unknown
Hacking Team
apt_group 🇮🇹 IT
Kinsing
apt_group 🇷🇺 RU
Tick
apt_group Information theft and espionage 🇨🇳 CN
Infy
apt_group Information theft and espionage 🇮🇷 IR
Andariel Group
apt_group 🇰🇷 KR
TeamTNT
apt_group 🇩🇪 DE
APT-C-36
apt_group Information theft and espionage 🇨🇴 CO
Roaming Mantis
apt_group 🇯🇵 JP
Rocke
apt_group 🇨🇳 CN
SEXi
apt_group
Operation Red Signature
apt_group Information theft and espionage 🇨🇳 CN
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Operation Shadow Force
apt_group 🇨🇳 CN
Operation Black Atlas
apt_group Financial crime

Triage Info

Decided atMar 03, 2026