VORANT. Threat Intelligence Sign in Get the full feed

Microsoft Patches Actively Exploited November 2022 Flaws

high vulnerability

IPA warns that several Microsoft vulnerabilities patched in November 2022, including two ProxyNotShell Exchange flaws, are being actively exploited.

Japan's IPA issued an alert following Microsoft's November 2022 Patch Tuesday release, highlighting that multiple vulnerabilities are confirmed to be under active exploitation. Among these are CVE-2022-41091, CVE-2022-41073, CVE-2022-41125, and CVE-2022-41128, along with two previously disclosed Exchange Server vulnerabilities (CVE-2022-41040 and CVE-2022-41082, known collectively as ProxyNotShell) that were first published on October 1, 2022 (JST).

Exploitation of these flaws could allow attackers to crash applications or gain control over affected systems, potentially leading to significant damage. IPA urges organizations to apply the available Microsoft patches immediately given the confirmed in-the-wild exploitation and the risk of expanding attack activity. The advisory does not attribute the exploitation to any specific threat actor and provides no additional technical detail beyond confirming active exploitation and urging prompt patching.

Mentioned in this report

Vulnerabilities CVE-2022-41040KEVCVE-2022-41073KEVCVE-2022-41082KEVCVE-2022-41091KEVCVE-2022-41125KEVCVE-2022-41128KEV

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/1109-ms.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free