SecOpsNews / news

RSS items as GitHub Issues for the discerning engineering leader or security professional
MIT License
38 stars 0 forks source link

[DataBreaches] Microsoft confirms new Exchange zero-days are used in attacks #3453

Closed github-actions[bot] closed 2 years ago

github-actions[bot] commented 2 years ago

Sergiu Gatlan reports: Microsoft has confirmed that two recently reported zero-day vulnerabilities in Microsoft Exchange Server 2013, 2016, and 2019 are being exploited in the wild. “The first vulnerability, identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, while the second, identified as CVE-2022-41082, allows remote code execution (RCE) when PowerShell is accessible to the attacker,” Microsoft said. Read more at Bleeping Computer.

https://www.databreaches.net/microsoft-confirms-new-exchange-zero-days-are-used-in-attacks/

github-actions[bot] commented 2 years ago

This issue is stale because it has been open 1 day with no activity. Remove stale label or comment or this will be closed in 1 day.

github-actions[bot] commented 2 years ago

This issue was closed because it has been stale with no activity.