High severity8.8CISA KEVNVD Advisory· Published Oct 3, 2022· Updated Jun 17, 2026
CVE-2022-41040
CVE-2022-41040
Description
Microsoft Exchange Server Elevation of Privilege Vulnerability
Affected products
11(expand)+ 5 more
- (no CPE)
- cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:*
- Microsoft/Microsoft Exchange Server 2013 Cumulative Update 23v5Range: 15.00.0
- Microsoft/Microsoft Exchange Server 2016 Cumulative Update 22v5Range: 15.0.0
- Microsoft/Microsoft Exchange Server 2019 Cumulative Update 11v5Range: 15.02.0
- Microsoft/Microsoft Exchange Server 2019 Cumulative Update 12v5Range: 15.02.0
- Microsoft/Microsoft Exchange Server 2016 Cumulative Update 23v5Range: 15.01.0
Patches
Vulnerability mechanics
References
6- msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41040nvdPatchVendor Advisory
- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41040nvdMitigationPatchVendor Advisory
- packetstormsecurity.com/files/170066/Microsoft-Exchange-ProxyNotShell-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.kb.cert.org/vuls/id/915563nvdThird Party AdvisoryUS Government Resource
- www.secpod.com/blog/microsoft-november-2022-patch-tuesday-patches-65-vulnerabilities-including-6-zero-days/nvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.