CVE-2022-41040
KEV RANSOMWAREHIGH 8.8EPSS 100.0%
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 99.96% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-09-30, used in ransomware campaigns
- Nuclei
- unknown
- Published
- 2022-10-03
- Updated
- 2025-10-21
Proof-of-concept exploits (11)
- http://packetstormsecurity.com/files/170066/Microsoft-Exchange-ProxyNotShell-Remote-Code-…
- 0-Gram/CVE-2022-410400★ · 2024-11-23
- CyprianAtsyor/LetsDefend-CVE-2022-41082-Exploitation-Attempt0★ · 2025-05-16
- ITPATJIDR/CVE-2022-410401★ · 2022-10-15
- Ph33rr/Exploit10★ · 2022-10-04
- TaroballzChen/CVE-2022-41040-metasploit-ProxyNotShell35★ · 2022-10-20
- d3duct1v/CVE-2022-410405★ · 2022-10-06
- kljunowsky/CVE-2022-41040-POC91★ · 2023-01-21
- numanturle/CVE-2022-4104019★ · 2022-10-02
- r3dcl1ff/CVE-2022-410405★ · 2022-10-04
- testanull/ProxyNotShell-PoC412★ · 2022-11-18