Remote Procedure Call Runtime Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? The authenticated attacker could take advantage of this vulnerability to execute malicious code through the RPC runtime.
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Any authenticated user could trigger this vulnerability. It does not require admin or other elevated privileges.
What is RPC runtime? See Remote procedure call (RPC) for more information on RPC and RPC Runtime.
🎯 Affected products42
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1909 for 32-bit Systems
- Windows 10 Version 1909 for ARM64-based Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows 10 Version 21H1 for 32-bit Systems
- Windows 10 Version 21H1 for ARM64-based Systems
- Windows 10 Version 21H1 for x64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows 8.1 for 32-bit systems
- Windows 8.1 for x64-based systems
- Windows RT 8.1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2
- +12 more not shown
✅ Remediation
KB5009557 (Security Update) — fixed build 10.0.17763.2452 KB5009545 (Security Update) — fixed build 10.0.18363.2037 KB5009543 (Security Update) — fixed build 10.0.19043.1466 KB5009555 (Security Update) — fixed build 10.0.20348.469 KB5009543 (Security Update) — fixed build 10.0.19042.1466 KB5009566 (Security Update) — fixed build 10.0.22000.434 KB5009543 (Security Update) — fixed build 10.0.19044.1466 KB5009585 (Security Update) — fixed build 10.0.10240.19177 KB5009546 (Security Update) — fixed build 10.0.14393.4886 KB5009610 (Monthly Rollup) — fixed build 6.1.7601.25829 KB5009621 (Security Only) — fixed build 6.1.7601.25829 KB5009624 (Monthly Rollup) — fixed build 6.3.9600.20246 KB5009595 (Security Only) — fixed build 6.3.9600.20246 KB5009627 (Monthly Rollup) — fixed build 6.0.6003.21349 KB5009601 (Security Only) — fixed build 6.0.6003.21349 KB5009586 (Monthly Rollup) — fixed build 6.2.9200.23584 KB5009619 (Security Only) — fixed build 6.2.9200.23584
🔗 References (31)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21922
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009557
- referencehttps://support.microsoft.com/help/5009557
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009545
- referencehttps://support.microsoft.com/help/5009545
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009543
- referencehttps://support.microsoft.com/help/5009543
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009555
- referencehttps://support.microsoft.com/help/5009555
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009566
- referencehttps://support.microsoft.com/help/5009566
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009585
- referencehttps://support.microsoft.com/help/5009585
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009546
- referencehttps://support.microsoft.com/help/5009546
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009610
- referencehttps://support.microsoft.com/help/5009610
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009621
- referencehttps://support.microsoft.com/help/5009621
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009624
- referencehttps://support.microsoft.com/help/5009624
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009595
- referencehttps://support.microsoft.com/help/5009595
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009627
- referencehttps://support.microsoft.com/help/5009627
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009601
- referencehttps://support.microsoft.com/help/5009601
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009586
- referencehttps://support.microsoft.com/help/5009586
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009619
- referencehttps://support.microsoft.com/help/5009619