New Microsoft Exchange Exploit Being Used To Breach Servers
The exploit allows threat actors to bypass ProxyNotShell URL rewrite mitigations and gain remote code execution (RCE) on vulnerable servers through Outlook Web Access (OWA). To execute arbitrary commands on compromised servers, the ransomware operators leverage Remote PowerShell to abuse the CVE-2022-41082 vulnerability. This new exploit chain is particularly concerning because it targets the Microsoft Exchange server, a critical component for many organizations. This server manages email communications within an organization, and a compromise of this server can have far-reaching consequences....