New Delhi: Microsoft has revealed it is investigating two new zero-day vulnerabilities affecting the company's Exchange Server which is actively being exploited by hackers. Microsoft said it is aware of limited targeted attacks using these two vulnerabilities. The company said an attacker would need authenticated access to the vulnerable Exchange Server, such as stolen credentials, to successfully exploit either of the two vulnerabilities.
"In these attacks, CVE-2022-41040 can enable an authenticated attacker to remotely trigger CVE-2022-41082. It should be noted that authenticated access to the vulnerable Exchange Server is necessary to successfully exploit either vulnerability," Microsoft said in a security update. The company was working on an accelerated timeline to release a fix. "Until then, we're providing mitigations and the detection guidance below to help customers protect themselves from these attacks," it added.