CVE-2022-41082
KEV RANSOMWAREHIGH 8.0EPSS 100.0%
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVSS v3.1
- 8.0 HIGH
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 99.97% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-09-30, used in ransomware campaigns
- Published
- 2022-10-03
- Updated
- 2025-10-21
Proof-of-concept exploits (11)
- http://packetstormsecurity.com/files/170066/Microsoft-Exchange-ProxyNotShell-Remote-Code-…
- CyprianAtsyor/LetsDefend-CVE-2022-41082-Exploitation-Attempt0★ · 2025-05-16
- SUPRAAA-1337/CVE-2022-410822★ · 2023-09-03
- balki97/OWASSRF-CVE-2022-41082-POC93★ · 2023-01-10
- bigherocenter/CVE-2022-41082-POC1★ · 2023-02-21
- notareaperbutDR34P3r/http-vuln-CVE-2022-410823★ · 2023-03-23
- notareaperbutDR34P3r/vuln-CVE-2022-410820★ · 2023-03-22
- ohnonoyesyes/CVE-2022-410801★ · 2022-12-23
- sikkertech/CVE-2022-410822★ · 2022-12-01
- soltanali0/CVE-2022-410823★ · 2024-10-24
- testanull/ProxyNotShell-PoC412★ · 2022-11-18