CVE-2022-21871HighCVSS 7.0
Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
🎯 Affected products31
- Microsoft Visual Studio 2015 Update 3
- Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)
- Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6)
- Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1909 for 32-bit Systems
- Windows 10 Version 1909 for ARM64-based Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows 10 Version 21H1 for 32-bit Systems
- Windows 10 Version 21H1 for ARM64-based Systems
- Windows 10 Version 21H1 for x64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
- +1 more not shown
✅ Remediation
KB5009557 (Security Update) — fixed build 10.0.17763.2452 KB5009545 (Security Update) — fixed build 10.0.18363.2037 KB5009543 (Security Update) — fixed build 10.0.19043.1466 KB5009555 (Security Update) — fixed build 10.0.20348.469 KB5009543 (Security Update) — fixed build 10.0.19042.1466 KB5009566 (Security Update) — fixed build 10.0.22000.434 KB5009543 (Security Update) — fixed build 10.0.19044.1466 KB5009585 (Security Update) — fixed build 10.0.10240.19177 KB5009546 (Security Update) — fixed build 10.0.14393.4886 KBRelease Notes (Security Update) — fixed build 15.9.44 KBRelease Notes (Security Update) — fixed build 16.7.25 KBRelease Notes (Security Update) — fixed build 16.9.17 KB5011164 (Security Update) — fixed build 27551.00
🔗 References (23)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21871
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009557
- referencehttps://support.microsoft.com/help/5009557
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009545
- referencehttps://support.microsoft.com/help/5009545
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009543
- referencehttps://support.microsoft.com/help/5009543
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009555
- referencehttps://support.microsoft.com/help/5009555
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009566
- referencehttps://support.microsoft.com/help/5009566
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009585
- referencehttps://support.microsoft.com/help/5009585
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009546
- referencehttps://support.microsoft.com/help/5009546
- patchhttp://aka.ms/vs/15/release/latest
- referencehttps://docs.microsoft.com/en-us/visualstudio/releasenotes/vs2017-relnotes
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.7
- referencehttps://docs.microsoft.com/en-us/visualstudio/releases/2019/release-notes-v16.7
- patchhttps://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.9
- referencehttps://docs.microsoft.com/en-us/visualstudio/releases/2019/release-notes-v16.9
- patchhttps://aka.ms/vs/14/release/5011164
- referencehttps://support.microsoft.com/help/5011164