CVE-2022-41082CISA KEVEPSS p100.0%

CVE-2022-41082Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft / Exchange Server

Description

Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution.

Scoring

CVSS 8.0 ()
VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS99.97% probability of exploitation · percentile 100.0% · 2026-08-04T12:00:14Z
Last modified2026-06-17

CISA KEV entry

Added to KEV: 2022-09-30

(incoming)1

TypeTargetConfidenceTier
KEVEntryMicrosoft Exchange Server Remote Code Execution Vulnerabilitykev-cve-2022-410820%live

Related by meaning· 5

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Microsoft Exchange Server Server-Side Request Forgery Vulnerability
CVE
Microsoft Exchange Server Privilege Escalation Vulnerability
CVE
Microsoft Exchange Server Information Disclosure Vulnerability
CVE
CVE-2026-45583
CVE
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.