{"id":13195,"date":"2023-01-02T14:28:00","date_gmt":"2023-01-02T13:28:00","guid":{"rendered":"http:\/\/nfirjun2026.local\/proxynotshell-new-vulnerabilities-in-microsoft-exchange-server-cve-2022-41040-cve-2022-41082-update\/"},"modified":"2024-02-12T14:12:41","modified_gmt":"2024-02-12T13:12:41","slug":"proxynotshell-new-vulnerabilities-in-microsoft-exchange-server-cve-2022-41040-cve-2022-41082-update","status":"publish","type":"post","link":"https:\/\/www.cyber-security-online.nl\/en\/proxynotshell-new-vulnerabilities-in-microsoft-exchange-server-cve-2022-41040-cve-2022-41082-update\/","title":{"rendered":"ProxyNotShell: New vulnerabilities in Microsoft Exchange Server (CVE-2022-41040, CVE-2022-41082) (update)"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"13195\" class=\"elementor elementor-13195 elementor-11417\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-06c4724 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"06c4724\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-fb77167\" data-id=\"fb77167\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-cca9d26 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"cca9d26\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-b11f1dc\" data-id=\"b11f1dc\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1234310 elementor-widget elementor-widget-text-editor\" data-id=\"1234310\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5><strong>Update January 2, 2023<\/strong><\/h5>\n<p><strong>Microsoft has released Nov. 8, 2022 security updates for Exchange Server 2013, 2016 and 2019. These protect against CVE-2022-41040 and CVE-2022-41082. NFIR at all times recommends installing patches as soon as they are available. These patches constitute the structural final measure and override the temporary mitigation measures.  <\/strong><\/p>\n<p>See also the FAQ section in the Microsoft blog:<br \/><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/released-november-2022-exchange-server-security-updates\/ba-p\/3669045\" target=\"_blank\" rel=\"noopener\">https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/released-november-2022-exchange-server-security-updates\/ba-p\/3669045<\/a><br \/>For environments still vulnerable to CVE-2022-41040 and CVE-2022-41082, new exploits are regularly published by security researchers. For example, see this Dec. 20, 2022 article from CrowdStrike:<\/p>\n<p><a href=\"https:\/\/www.crowdstrike.com\/blog\/owassrf-exploit-analysis-and-recommendations\/\" target=\"_blank\" rel=\"noopener\">OWASSRF: CrowdStrike Identifies New Method for Bypassing ProxyNotShell Mitigations<\/a><\/p>\n<p>This means that the temporary measures published as a workaround in 2022 are no longer sufficient to close these CVE vulnerabilities. Keeping Exchange up to date with the latest patches from Microsoft is the motto. The recommendation is to have at least patch level November 2022 for Exchange Server to protect against CVE-2022-41040 and CVE-2022-41082.<\/p>\n<p>===<\/p>\n<p><strong>A set of two new zero-day vulnerabilities for Microsoft Exchange Servers &#8211; ProxyNotShell, disclosed by GTSC on Sept. 29, 2022, is currently being actively exploited by hackers. No patch is available at the time of writing.<\/strong><\/p>\n<p>Microsoft published a &#8220;Customer Guidance&#8221; article in the Microsoft Security Response Center on the morning of Sept. 30, 2022, in which Microsoft confirms it is investigating two reported zero-day vulnerabilities. They are CVE-2022-41040, a Server-Side Request Forgery (SSRF) vulnerability and CVE-2022-41082, a Remote Code Execution (RCE) vulnerability if PowerShell is accessible to the attacker.<\/p>\n<p>Microsoft is aware of limited targeted attacks exploiting the vulnerabilities to get into victims&#8217; systems. In these attacks, CVE-2022-41040 can enable an &#8220;authenticated&#8221; attacker (i.e., the attacker must already have a successful successful login to the affected environment) to then trigger CVE-2022-41082. It should be noted that authenticated access to the vulnerable Exchange Server is required to successfully exploit one of the two vulnerabilities. The vulnerability uses what is known as Autodiscover functionality. URLs using Autodiscover do not have Multi-Factor Authentication (MFA) protection.<\/p>\n<p><em><strong>Microsoft is currently working on a patch.<\/strong><\/em><\/p>\n<p>These vulnerabilities are very similar to vulnerabilities reported last year called ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207). The vulnerability has been labeled in the cybersecurity community (see Twitter @GossiTheDog) as <a href=\"https:\/\/twitter.com\/search?q=ProxyNotShell\" target=\"_blank\" rel=\"noopener\">#ProxyNotShell<\/a>.<br \/>Until there is a patch, it is highly recommended to follow mitigation and detection guidelines to help customers protect themselves from these attacks.<\/p>\n<p>Microsoft Exchange Online already has detection and mitigation to protect customers. Only environments with Microsoft Exchange Server (on-premises or hybrid, versions Server 2013, Server 2016, Server 2019) are potentially vulnerable.<\/p>\n<p style=\"-webkit-font-smoothing: antialiased; margin-bottom: 0px;\"><span style=\"-webkit-font-smoothing: antialiased; font-size: 11pt;\"><span style=\"-webkit-font-smoothing: antialiased;\"><span style=\"-webkit-font-smoothing: antialiased;\"><b><i>Update October 3, 2022:<\/i><\/b><\/span><\/span><\/span><\/p>\n<p style=\"-webkit-font-smoothing: antialiased; margin-bottom: 0px;\"><span style=\"-webkit-font-smoothing: antialiased; font-size: 11pt; font-style: inherit; font-weight: inherit;\">Microsoft has published an update to the &#8220;Customer Guidance&#8221; article.<\/span><\/p>\n<ul style=\"-webkit-font-smoothing: antialiased; clear: left;\">\n<li style=\"-webkit-font-smoothing: antialiased; margin-left: 8px;\"><span style=\"-webkit-font-smoothing: antialiased; font-size: 11pt; font-style: inherit; font-weight: inherit;\">A script can be used to execute mitigation measures in an automated manner, see <a style=\"-webkit-font-smoothing: antialiased; outline-style: none; color: #4f52b2;\" tabindex=\"-1\" title=\"https:\/\/microsoft.github.io\/CSS-Exchange\/Security\/EOMTv2\/\" href=\"https:\/\/microsoft.github.io\/CSS-Exchange\/Security\/EOMTv2\/\" target=\"_blank\" rel=\"noopener noreferrer\" aria-label=\"Koppeling https:\/\/microsoft.github.io\/CSS-Exchange\/Security\/EOMTv2\/\">https:\/\/microsoft.github.io\/CSS-Exchange\/Security\/EOMTv2\/<\/a><\/span><\/li>\n<li style=\"-webkit-font-smoothing: antialiased; margin-left: 8px;\"><span style=\"-webkit-font-smoothing: antialiased; font-size: 11pt; font-style: inherit; font-weight: inherit;\">Additional information on detection capabilities have been added<\/span><\/li>\n<li style=\"-webkit-font-smoothing: antialiased; margin-left: 8px;\"><span style=\"-webkit-font-smoothing: antialiased; font-size: 11pt; font-style: inherit; font-weight: inherit;\">The recommendation about shutting down Remote Powershell has been changed to instructions to disable remote PowerShell for users who are not administrators, see <a style=\"-webkit-font-smoothing: antialiased; outline-style: none; color: #4f52b2;\" tabindex=\"-1\" title=\"%20%\" href=\"https:\/\/learn.microsoft.com\/en-us\/powershell\/exchange\/control-remote-powershell-access-to-exchange-servers?view=exchange-ps%22%20%5Cl%20%22use-the-exchange-management-shell-to-enable-or-disable-remote-powershell-access-for-a-user\" target=\"_blank\" rel=\"noopener noreferrer\" aria-label=\"Koppeling https:\/\/learn.microsoft.com\/en-us\/powershell\/exchange\/control-remote-powershell-access-to-exchange-servers?view=exchange-ps%22%20\\l%20%22use-the-exchange-management-shell-to-enable-or-disable-remote-powershell-access-for-a-user\">%20%<\/a><\/span><\/li>\n<li style=\"-webkit-font-smoothing: antialiased; margin-left: 8px;\"><span style=\"-webkit-font-smoothing: antialiased; font-size: 11pt; font-style: inherit; font-weight: inherit;\">NFIR recommends checking Microsoft&#8217;s &#8220;Customer Guidance&#8221; regularly for updates. It is plausible that security researchers will find new &#8220;bypasses&#8221; to get around the mitigation measures. In response, it is likely that Microsoft will publish additional enhanced mitigation measures.<\/span><\/li>\n<li style=\"-webkit-font-smoothing: antialiased; margin-left: 8px;\"><span style=\"-webkit-font-smoothing: antialiased; font-size: 11pt; font-style: inherit; font-weight: inherit;\">The link to the Customer Guidance article is unchanged (content has been updated) and can be found here: <\/span><a style=\"-webkit-font-smoothing: antialiased; outline-style: none; color: #4f52b2;\" tabindex=\"-1\" title=\"https:\/\/msrc-blog.microsoft.com\/2022\/09\/29\/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server\/\" href=\"https:\/\/msrc-blog.microsoft.com\/2022\/09\/29\/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server\/\" target=\"_blank\" rel=\"noopener noreferrer\" aria-label=\"Koppeling https:\/\/msrc-blog.microsoft.com\/2022\/09\/29\/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server\/\">https:\/\/msrc-blog.microsoft.com\/2022\/09\/29\/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server\/<\/a><\/li>\n<\/ul>\n<p style=\"-webkit-font-smoothing: antialiased; margin-bottom: 0px; margin-left: 48px;\">\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-f4bff09\" data-id=\"f4bff09\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-996aa7a elementor-widget elementor-widget-image\" data-id=\"996aa7a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/www.cyber-security-online.nl\/en\/incident-response-specialist-24-7-availability\/\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"512\" height=\"447\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/09\/MS-Exchange-logo.png\" class=\"attachment-full size-full wp-image-11419\" alt=\"ProxyNotShell: New vulnerabilities in Microsoft Exchange Server (CVE-2022-41040, CVE-2022-41082) (update)\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/09\/MS-Exchange-logo.png 512w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/09\/MS-Exchange-logo-300x262.png 300w\" sizes=\"(max-width: 512px) 100vw, 512px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-49b2fd5 elementor-widget elementor-widget-button\" data-id=\"49b2fd5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2023\/01\/NFIR-Threat-Intelligence-Report-ProxyNotShell-Nieuwe-Kwetsbaarheden-in-Microsoft-Exchance-Server-CVE-2022-41040-CVE-2022-41082-v1.1.pdf\" target=\"_blank\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"far fa-file-pdf\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download the Threat Intel Report here<br>  ProxyNotShell: New vulnerabilities in Microsoft Exchange Server<br>  (CVE-2022-41040, CVE-2022-41082)<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c689935 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c689935\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c944514\" data-id=\"c944514\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-44aa2a9 nfir-from-uael-faq nfir-faq-schema elementor-widget elementor-widget-accordion\" data-id=\"44aa2a9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-7201\" class=\"elementor-tab-title\" data-tab=\"1\" role=\"button\" aria-controls=\"elementor-tab-content-7201\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What potential impact does this Confluence vulnerability have? <\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-7201\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"1\" role=\"region\" aria-labelledby=\"elementor-tab-title-7201\"><p>If an attacker is able to successfully exploit the vulnerability, it can lead to the execution of unauthorized code on the affected systems. This could potentially result in the server and the data present being compromised. This attack can be carried out from the Internet requiring authentication.<br>From a compromised server, an attacker may be able to gain access to the machine and possibly to the rest of the network.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-7202\" class=\"elementor-tab-title\" data-tab=\"2\" role=\"button\" aria-controls=\"elementor-tab-content-7202\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">How is the Confluence vulnerability detectable?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-7202\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"2\" role=\"region\" aria-labelledby=\"elementor-tab-title-7202\"><p>Microsoft has included a number of specific mitigation measures in the &#8220;Customer Guidance&#8221; report (see <a href=\"https:\/\/msrc-blog.microsoft.com\/2022\/09\/29\/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server\/\" target=\"_blank\" rel=\"noopener\">https:\/\/msrc-blog.microsoft.com\/2022\/09\/29\/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server\/<\/a><br>NFIR strongly recommends implementing these measures.<br>At the time of writing, no patches have been published by Microsoft &#8211; however, Microsoft&#8217;s article described a number of workarounds that are summarized below:<\/p><p> <\/p><p> <\/p><ul><li><strong>Mitigation 1:<\/strong> In IIS Manager, block so-called Autodiscover URLs based on the now known URL patterns; see the instructions published by Microsoft for this purpose<br>(see <a href=\"https:\/\/msrc-blog.microsoft.com\/2022\/09\/29\/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server\/\" target=\"_blank\" rel=\"noopener\">https:\/\/msrc-blog.microsoft.com\/2022\/09\/29\/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server\/)<\/a>.<\/li><li><strong>Mitigation 2<\/strong>: Block the ports used by &#8220;Remote PowerShell.<br>This refers to HTTP: 5985 and HTTPS: 5986.<\/li><li><strong>\n  <strong>Mitigation 3:<\/strong>\n<\/strong><strong>NFIR <\/strong>also recommends the following as <strong>Mitigation 3<\/strong>: If there is no need at all for making Outlook Web Access (OWA) available on the Internet; block OWA altogether.<\/li><\/ul><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-7203\" class=\"elementor-tab-title\" data-tab=\"3\" role=\"button\" aria-controls=\"elementor-tab-content-7203\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Is there an action plan that your organization can follow?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-7203\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"3\" role=\"region\" aria-labelledby=\"elementor-tab-title-7203\"><p>If you don&#8217;t know if you have vulnerable Outlook Web App services available on the Internet, you can search <a href=\"https:\/\/www.shodan.io\/\" target=\"_blank\" rel=\"noopener\">Shodan.io<\/a> website with:<\/p><blockquote><p>http.component: &#8220;outlook web app&#8221; and by adding the filter<br>org:yourorganizationname or ssl: &#8220;*yourorganizationname&#8221;<\/p><\/blockquote><p>Details of the mitigation measures can be found in the Microsoft article (see <a href=\"https:\/\/msrc-blog.microsoft.com\/2022\/09\/29\/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server\/\" target=\"_blank\" rel=\"noopener\">https:\/\/msrc-blog.microsoft.com\/2022\/09\/29\/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server\/)<\/a><\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-7204\" class=\"elementor-tab-title\" data-tab=\"4\" role=\"button\" aria-controls=\"elementor-tab-content-7204\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Is there an action plan that your organization can follow? <\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-7204\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"4\" role=\"region\" aria-labelledby=\"elementor-tab-title-7204\"><p>It is important for your organization to take at least the following steps:<\/p><ol><li>Check publicly available Indicators-of-Compromise (IoCs) on your systems to determine if any systems may have been compromised, or have external preventive research performed on your systems.<\/li><li>Implement the workarounds made available to reduce the impact, where possible.<\/li><li>Prepare your organization for the situation when patches need to be executed unexpectedly (outside the regular update timeframes) and apply patches in a controlled manner according to the procedure usual for your organization.<\/li><li>Immediately run the available security updates\/patches as soon as they are published on the systems and verify that the updates have actually been applied. In case you have an external IT service provider: Have your provider perform these actions and have them confirm the actions and their result to you in writing.<\/li><\/ol><p>Do you have systems where the risk is high (for example, systems with very sensitive or special personal data)? If so, do you possibly have indications that the system cannot be mitigated and\/or updated immediately? Then consider temporarily disabling the system until it can be updated.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-7205\" class=\"elementor-tab-title\" data-tab=\"5\" role=\"button\" aria-controls=\"elementor-tab-content-7205\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What should your organization do in case of potential abuse?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-7205\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"5\" role=\"region\" aria-labelledby=\"elementor-tab-title-7205\"><p>If your organization is suspected to have been the victim of an attack, the urgent advice is to have research conducted into the cause, to what extent attackers may have compromised other systems and what information may have been accessed unauthorized.<\/p><ol><li>If possible, disconnect affected systems from the network, but leave them on (in connection with any traces such as volatile memory &#8211; RAM);<\/li><li>Have the affected systems forensically examined; ensure adequate backups;<\/li><li>Reset your passwords and user data;<\/li><li>Report to the Police;<\/li><li>Consider filing a report with the Personal Data Authority.<\/li><\/ol><p>Does your organization currently have an incident?  <a href=\"https:\/\/www.cyber-security-online.nl\/en\/security-incident-call-us-24-7\/\">Our Computer Emergency Response Teams  <\/a><br>(CERT) are available to organizations 24\/7 to support IT Security Incidents.<br>Then call <a href=\"tel:+31881330700\">088 133 0700<\/a> and we will do our best to help you as soon as possible.<\/p><p><a href=\"https:\/\/www.cyber-security-online.nl\/en\/incident-response-specialist-24-7-availability\/\">Learn more about our Incident Response Service<\/a><\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c8e9788 elementor-widget elementor-widget-text-editor\" data-id=\"c8e9788\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Does your organization currently have an incident? Our Computer Emergency Response Teams (CERT) are available to organizations 24\/7 to support IT Security Incidents.<\/p>\n<p>Then call<a href=\"tel:+31881330700\"> 088 133 0700<\/a> and we will do our best to help you as soon as possible. Here you will find more <a href=\"https:\/\/www.cyber-security-online.nl\/en\/incident-response-specialist-24-7-availability\/\" data-wplink-edit=\"true\">information about our Incident Response <\/a>service.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9997d22 elementor-widget elementor-widget-button\" data-id=\"9997d22\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2023\/01\/NFIR-Threat-Intelligence-Report-ProxyNotShell-Nieuwe-Kwetsbaarheden-in-Microsoft-Exchance-Server-CVE-2022-41040-CVE-2022-41082-v1.1.pdf\" target=\"_blank\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"far fa-file-pdf\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download the Threat Intelligence Report on vulnerability in Confluence (CVE-2022-26134) here.<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b68b35c elementor-widget elementor-widget-text-editor\" data-id=\"b68b35c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em>Disclaimer: NFIR has made every effort to make this information accurate and reliable. However, the information provided is without any guarantee of any kind and its use is entirely at the risk of the user. NFIR assumes no responsibility or liability for the accuracy, content, completeness, legality or reliability of the information provided.<\/em><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Update January 2, 2023 Microsoft has released Nov. 8, 2022 security updates for Exchange Server 2013, 2016 and 2019. These protect against CVE-2022-41040 and CVE-2022-41082. [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":11419,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_titles_title":"ProxyNotShell: New vulnerabilities in Microsoft Exchange Server (CVE-2022-41040, CVE-2022-41082) (update)","_seopress_titles_desc":"Take additional protective measures to prevent more damage from being done.Check regularly to see if a system is no longer directly open to the Internet.Check regularly on \"Shodan\" and through other search engines to see if your own systems on the Internet are open to external connectivity as planned. Briefly: Microsoft Exchange Server 2013, 2016 and 2019 contain vulnerabilities (CVE-2022-41040 and CVE-2022-41082) that can be exploited by attackers. Microsoft is working on a patch. Implement mitigating measures immediately to protect against these zero-day vulnerabilities using","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"40","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/09\/MS-Exchange-logo.png","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/09\/MS-Exchange-logo.png","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"both","_seopress_redirections_param":"","_seopress_redirections_type":301,"_seopress_analysis_target_kw":"","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[29,51],"tags":[],"class_list":["post-13195","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-media-en","category-threat-intelligence-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts\/13195","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/comments?post=13195"}],"version-history":[{"count":0,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts\/13195\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media\/11419"}],"wp:attachment":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media?parent=13195"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/categories?post=13195"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/tags?post=13195"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}