CVE-2022-22017CriticalCVSS 8.8

Remote Desktop Client Remote Code Execution Vulnerability

Published
May 10, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How would an attacker exploit this vulnerability? An attacker would have to convince a targeted user to connect to a malicious RDP server. Upon connecting, the malicious server could execute code on the victim's system in the context of the targeted user.

🎯 Affected products5

  • Remote Desktop client for Windows Desktop
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)

✅ Remediation

KBRelease Notes (Security Update) — fixed build 1.2.3130 KB5013944 (Security Update) — fixed build 10.0.20348.707 KB5013943 (Security Update) — fixed build 10.0.22000.675

🔗 References (6)