Microsoft Exchange Server Server-Side Request Forgery Vulnerability
Vendor: Microsoft
Product: Exchange Server
Added: 2022-09-30
Due Date: 2022-10-21
Description:
Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.
Required Action:
Apply updates per vendor instructions.
CWEs: