Microsoft has confirmed that two recently identified zero-days in Microsoft Exchange Server 2013, 2016, and 2019 are being used in ongoing attacks. According to Microsoft, “The first vulnerability, identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, while the second, identified as CVE-2022-41082, allows Remote Code Execution (RCE) when PowerShell is accessible to the attacker.” Microsoft added that CVE-2022-41040 can only be exploited by authenticated attackers. Successful exploitation then allows them to trigger the CVE-2022-41082 RCE vulnerability. According to researchers at GTSC, the zero-days are chained to deploy Chinese Chopper web shells for persistence and data theft and to move laterally through the victims’ networks. Researchers also believe that the ongoing attacks are likely the work of a Chinese threat actor.
12 Essentials for a Successful SOC Partnership
As cyber threats continue to impact businesses of all sizes, the need for round-the-clock security