
Scripts de Nmap para detectar la vulnerabilidad 0-day de Exchange (CVE-2022-41082)
Scripts NSE de Nmap para comprobar la vulnerabilidad de Exchange (CVE-2022-41082). Los scripts NSE comprueban los servicios expuestos más populares en Internet. Es un script básico que verifica si el parcheo virtual funciona.
Dado que actualmente no existe un parche, solo se comprueban las soluciones alternativas para determinar si el host es vulnerable.
Ejemplo sencillo:
nmap -sV -T4 -v --script=http-vuln-cve-2022 scanme.nmap.org
Ejecución más rápida (subredes grandes):
nmap -p443 -T4 -v --script=http-vuln-cve-2022 10.0.0.0/16
Vulnerable:
nmap -Pn -T4 -p443 --script=http-vuln-cve2022-41082.nse 127.0.0.1
Starting Nmap 7.92 ( https://nmap.org ) at 2022-10-01 13:37 CEST
Nmap scan report for localhost (127.0.0.1)
Host is up (0.030s latency).
PORT STATE SERVICE
443/tcp open https
| http-vuln-cve2022-41082:
| VULNERABLE:
| Microsoft Exchange - 0-day RCE
| State: VULNERABLE
| IDs: CVE:CVE-2022-41082
| Risk factor: High CVSSv2: 10.0 (HIGH) (AV:N/AC:L/AU:N/C:C/I:C/A:C)
| Exchange 0-day vuln: CVE-2022-41082
|
| Disclosure date: 2022-09-29
| References:
| https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41082
| https://microsoft.github.io/CSS-Exchange/Security/EOMTv2/
| https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/
|_ https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
Nmap done: 1 IP address (1 host up) scanned in 0.59 seconds
nmap -Pn -T4 -p443 --script=http-vuln-cve2022-41082.nse scanme.nmap.org
Starting Nmap 7.92 ( https://nmap.org ) at 2022-10-01 13:39 CEST
Nmap scan report for scanme.nmap.org (45.33.32.156)
Host is up (0.17s latency).
PORT STATE SERVICE
443/tcp closed https
Nmap done: 1 IP address (1 host up) scanned in 1.62 seconds
Referencias generales y enlaces a la vulnerabilidad
Microsoft Blog - Blog de Microsoft sobre CVE-2022-41082
Microsoft Mitigation Tool - Microsoft Exchange On-premises Mitigation Tool v2
Microsoft Guidance - Orientación de Microsoft para clientes sobre vulnerabilidades de día cero reportadas en Microsoft Exchange Server
VNCCERT-CC 0dayex-checker - Comprobador de día cero para Microsoft Exchange Server (comprobador de parcheo virtual)
Escrito por Vlatko Kosturjak (Diverto). Gracias a Dalibor S.