Authenticated SSRF via Autodiscover-to-PowerShell request routing
Published Oct 3, 2022 · Updated Oct 21, 2025
Server-side request forgery in Microsoft Exchange Server 2013, 2016, and 2019 allows remote authenticated users to reach backend services. The front-end request pipeline accepts a crafted URL containing Autodiscover and PowerShell path elements and proxies it to the PowerShell backend without enforcing the intended destination boundary. A standard Exchange account is sufficient; the flaw supports server-side requests and can be chained with a PowerShell deserialization flaw for code execution.
Summary
What happened
Server-side request forgery in Microsoft Exchange Server 2013, 2016, and 2019 allows remote authenticated users to reach backend services. The front-end request pipeline accepts a crafted URL containing Autodiscover and PowerShell path elements and proxies it to the PowerShell backend without enforcing the intended destination boundary. A standard Exchange account is sufficient; the flaw supports server-side requests and can be chained with a PowerShell deserialization flaw for code execution.
The record
- CVE
- CVE-2022-41040
- Published
- Oct 3, 2022
- Updated
- Oct 21, 2025
- Vendor
- Microsoft
- Product
- Microsoft Exchange Server 2019 Cumulative Update 12
- Classifications
- CWE-918, T1190
- Attack vector
- network
- Privileges
- authenticated
Timeline
How it unfolded
- Aug 1, 2022Exploitation reportedLimited targeted ProxyNotShell exploitation
- Oct 3, 2022CVE publishedPublication date reported by the CVE source.
- Oct 21, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=15.02.0 <15.02.1118.020
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Microsoft Exchange ProxyNotShell RCE Metasploit moduleweaponized · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Reported exploitation
- Limited targeted ProxyNotShell exploitationreported exploitation
- CISA Known Exploited Vulnerabilities listingknown exploited catalog
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo