Microsoft Patches Actively Exploited November 2022 Flaws
IPA warns that several Microsoft vulnerabilities patched in November 2022, including two ProxyNotShell Exchange flaws, are being actively exploited.
Japan's IPA issued an alert following Microsoft's November 2022 Patch Tuesday release, highlighting that multiple vulnerabilities are confirmed to be under active exploitation. Among these are CVE-2022-41091, CVE-2022-41073, CVE-2022-41125, and CVE-2022-41128, along with two previously disclosed Exchange Server vulnerabilities (CVE-2022-41040 and CVE-2022-41082, known collectively as ProxyNotShell) that were first published on October 1, 2022 (JST).
Exploitation of these flaws could allow attackers to crash applications or gain control over affected systems, potentially leading to significant damage. IPA urges organizations to apply the available Microsoft patches immediately given the confirmed in-the-wild exploitation and the risk of expanding attack activity. The advisory does not attribute the exploitation to any specific threat actor and provides no additional technical detail beyond confirming active exploitation and urging prompt patching.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/1109-ms.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free