Exchange CU13 and latest SU, yet external scan(s) claim CVE-2022-41040 CVE-2022-41082 vulnerability.

Ayukii 0 Reputation points
2024-04-29T15:13:10.5166667+00:00

Per Exchange Health Checker version 24.03.12.1700 this is my Exchange version.

Build Number: 15.02.1258.032

Exchange IU or Security Hotfix Detected: Security Update for Exchange Server 2019 Cumulative Update 13 (KB5036402)

We always run one CU behind the latest, and we pay for external vulnerability scans. So when CU12 went end of life we upgraded to CU13, and then our SOC began telling us that our Microsoft Exchange Server OWA has (KB5019758, ProxyNotShell) CVE-2022-41040: Server-Side Request Forgery (SSRF) and CVE-2022-41082: Remote code execution (RCE) vulnerabilities.

So I do my own external vulnerability scan using NMAP and the following scripts, which too claim the server is vulnerable.

https://github.com/Diverto/nse-exchange CVE-2022-1040_checker

https://github.com/Diverto/nse-exchange http-vuln-cve2022-41082.nse

Yet, we were, and are, patched to the point that these vulnerabilities should not exist. Also the Exchange Heath Checker Script should tell me if we're vulnerable, yet it does not. Even the EOMTv2.ps1 script used to make URL rewrite rules to mitigate this attack in the first place now says: VERBOSE: Checking if EOMTv2 is up to date with https://aka.ms/EOMTv2-VersionsUri VERBOSE: Starting EOMTv2.ps1 version 23.11.21.1852 on MAIL VERBOSE: EOMTv2 preCheck complete on MAIL NOTICE: CVE-2022-41040 vulnerability has been fixed for the Exchange build running on this computer - mitigation will not be applied.

So here's the question(s)/assumption; When Microsoft released CU13 and the SU's to fix those CVE's, and we went from CU12 to CU13, wiping away those URL rewrite kludges, was my SOC, and those NMAP scripts, now supposed to be fooled into thinking the Exchange server has this vulnerability?

Is there an external vulnerability scan I can try, other than what I already have, that I can be sure is telling me the truth?

Microsoft Exchange Online
Exchange Server
Exchange Server
A family of Microsoft client/server messaging and collaboration software.
1,103 questions
Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,241 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,398 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,910 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 142.7K Reputation points MVP
    2024-04-29T20:48:15.0633333+00:00

    I always go by what the Exchange Health Checker says. Not sure what that external scanning is going by honestly. BTW, if you are on CU13, you are really two builds behind. Hopefully you have Extended Protection Enabled!

    https://learn.microsoft.com/en-us/exchange/new-features/build-numbers-and-release-dates?view=exchserver-2019

    1 person found this answer helpful.