For those of you who still run Exchange on-prem, there are 2 zero days currently being exploited in the wild:
CVE-2022-41040: A Server Side Request Forgery (SSRF) issue.
CVE-2022-41082: A remote code execution (RCE) issue.
No information on when there will be a patch.
To mitigate, add a blocking rule in “IIS Manager -> Default Web Site -> Autodiscover -> URL Rewrite -> Actions”
- “.*autodiscover\.json.*\@.*Powershell.*” (excluding quotes)
More guidance here: https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/