What this checks: whether a Microsoft Exchange host runs a version affected by unauth-reachable EoP chained with OWASSRF SSRF (CVE-2022-41082) for RCE. Read-only: it fingerprints Microsoft Exchange and reads the version, no exploitation.
3. Detection — reads the Microsoft Exchange version from the version exposed at /owa/auth/logon.aspx, compares to Nov 2022 SU (KB5019758): 2013 CU23 15.0.1497.44 | 2016 CU22 15.1.2375.37 | 2016 CU23 15.1.2507.16 | 2019 CU11 15.2.986.36 | 2019 CU12 15.2.1118.20. Flags vulnerable on an affected build. No exploitation.
1. Target List — paste your Microsoft Exchange URLs here, one per line (e.g. https://host.example.com).
Overview
This workflow finds Microsoft Exchange Server and sorts each host by whether its OWA build falls below the CVE-2022-41080 fixed floors. CVE-2022-41080 is privilege escalation on Exchange that was patched in the November 2022 security updates. This check never exercises OWASSRF or ProxyNotShell and never sends a privilege-escalation exploit. Give it hostnames, IP addresses, or URLs you are authorised to test. The workflow GETs /owa/auth/logon.aspx, fingerprints Exchange from OWA markers on that page, parses the version from the /owa/auth/<build>/ path, and compares that tuple to the 15.0, 15.1, and 15.2 bands in the graph. Every host comes back affected or not, so a fleet advisory becomes an evidenced list for exposure management. There is no POST or SOAP confirm and no RCE claim.
Run it on a schedule when CAS hosts turn over. A restored mailbox role that lands on a pre-SU build is the reason the same fingerprint stays useful.
Pipeline
Read the target list. Hosts, URLs, or ranges, one per line, become the scope.
GET /owa/auth/logon.aspx on each host and fingerprint Exchange from markers such as /owa/auth/, logon.aspx, X-OWA-Version, and Microsoft Exchange strings.
Parse the build from the /owa/auth/<n.n.n.n>/ path and compare it to the CVE-2022-41080 15.0 / 15.1 / 15.2 floors in the graph.
Collect the per-host rows: product match, version, vulnerable flag, and any fetch error.
Emit the summary counts: hosts checked, product hits, vulnerable, and errors.
Inputs
Target scope. Hostnames, IP addresses, CIDR ranges, or URLs, one per line. Full URLs and host:port entries work too, since the workflow normalizes each into a bare host. Point it at scope you are authorised to test.
Outputs
results.jsonl. One row per host: URL, whether Exchange was detected, the version read, the vulnerable flag, and detail text.
findings.jsonl. The same per-host verdict shaped for triage, with severity set from the vulnerable flag.
summary.json. Counts across the list: targets, product hits, vulnerable, and errors, plus the detection notes from the graph.
Integrations
HTTP. Unauthenticated GET of /owa/auth/logon.aspx only. No OWASSRF, no ProxyNotShell exploit, and no privilege-escalation confirm.
Sample output
The records below are illustrative and do not come from a real run. They show one Exchange host below a CVE-2022-41080 floor, one at or above its band floor, and one host that is not the product.
Builds below the 15.0 / 15.1 / 15.2 floors in the graph: 15.0.1497.44, 15.1.2375.37, 15.1.2507.16, 15.2.986.36, and 15.2.1118.20. A version picks the matching band, then compares to that band's floor. When no band matches, the graph falls back to FIXED 15.2.1118.20. The compare uses the OWA path version on /owa/auth/logon.aspx.
Does an affected row mean privilege escalation worked?
No. The check only GETs /owa/auth/logon.aspx and reads the OWA version path. It does not exercise OWASSRF or ProxyNotShell, does not POST or SOAP, and does not confirm privilege escalation or RCE.
Is this check safe on production?
Yes. It is a read-only unauthenticated GET of the public OWA logon page. It does not log in or send an exploit payload.
Does the check need credentials?
No. It fingerprints the public OWA logon page the way an external scanner would.
What is CVE-2022-41080?
Privilege escalation in Microsoft Exchange Server addressed in the November 2022 security updates. This workflow maps hosts to that CVE by OWA version exposure only.