High severity8.0CISA KEVNVD Advisory· Published Oct 3, 2022· Updated Jun 17, 2026
CVE-2022-41082
CVE-2022-41082
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
Affected products
11cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:*
- (no CPE)
- Microsoft/Microsoft Exchange Server 2013 Cumulative Update 23v5Range: 15.00.0
- Microsoft/Microsoft Exchange Server 2016 Cumulative Update 22v5Range: 15.0.0
- Microsoft/Microsoft Exchange Server 2016 Cumulative Update 23v5Range: 15.01.0
- Microsoft/Microsoft Exchange Server 2019 Cumulative Update 11v5Range: 15.02.0
- Microsoft/Microsoft Exchange Server 2019 Cumulative Update 12v5Range: 15.02.0
Patches
Vulnerability mechanics
References
8- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41082nvdPatchVendor Advisory
- packetstormsecurity.com/files/170066/Microsoft-Exchange-ProxyNotShell-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41082nvdVendor Advisory
- www.kb.cert.org/vuls/id/915563nvdThird Party AdvisoryUS Government Resource
- www.secpod.com/blog/microsoft-november-2022-patch-tuesday-patches-65-vulnerabilities-including-6-zero-days/nvdThird Party Advisory
- www.vicarius.io/vsociety/posts/cve-2022-41082-microsoft-exchange-server-remote-code-execution-vulnerability-detection-scriptnvdThird Party Advisory
- www.vicarius.io/vsociety/posts/cve-2022-41082-microsoft-exchange-server-remote-code-execution-vulnerability-mitigation-scriptnvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
2- New SharkLoader Malware Deploys Cobalt Strike in StrikeShark CyberattacksThe Hacker News · Jun 26, 2026
- StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoaderSecurelist · Jun 24, 2026