ProxyNotShell (Sept 2022): The Third Major Exchange Zero-Day Wave
Retrospective: this article looks back at events from September 2022, written in 2026 with the benefit of hindsight.
On September 29, 2022, Microsoft confirmed two zero-day vulnerabilities in on-premises Microsoft Exchange Server being exploited in limited, targeted attacks: CVE-2022-41040 (server-side request forgery) and CVE-2022-41082 (remote code execution via PowerShell). Researchers nicknamed them ProxyNotShell.
What made it different
Unlike ProxyLogon and ProxyShell, exploitation required an authenticated user — any valid mailbox credentials. Given how many credentials are stolen and sold, that was a modest barrier.
The patching gap
Microsoft didn't release patches until November 2022 — about six weeks after confirmation. In the meantime, it published mitigations: URL rewrite rules in IIS and disabling remote PowerShell for non-admin users. Researchers found ways to bypass the initial URL rewrite mitigation, and Microsoft updated its guidance several times. The Exchange Emergency Mitigation service applied some mitigations automatically.
Why it mattered
ProxyNotShell was the third major wave of Exchange Server attacks in under two years. For many organizations, it was the final argument for completing migration to Exchange Online and retiring on-premises servers. Exchange Online customers were not affected.
Lessons in hindsight
- Mitigations aren't patches. Track vendor updates closely when relying on workarounds.
- Authenticated vulnerabilities still matter when credentials are cheap.
- Disable remote PowerShell for users who don't need it.
- Reduce attack surface by retiring internet-facing servers you don't need.
In hindsight
Microsoft later made it possible for many hybrid customers to remove their last Exchange server. Organizations that did no longer faced this recurring emergency cycle.
- How to Decommission the Last Exchange Server in a Hybrid Deployment How-To & Hardening
- Detecting Exchange Zero-Day: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: When to Finally Leave On-Prem Exchange CIO Briefings