CVE-2022-22017CriticalCVSS 8.8
Remote Desktop Client Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How would an attacker exploit this vulnerability? An attacker would have to convince a targeted user to connect to a malicious RDP server. Upon connecting, the malicious server could execute code on the victim's system in the context of the targeted user.
🎯 Affected products5
- Remote Desktop client for Windows Desktop
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
✅ Remediation
KBRelease Notes (Security Update) — fixed build 1.2.3130 KB5013944 (Security Update) — fixed build 10.0.20348.707 KB5013943 (Security Update) — fixed build 10.0.22000.675
🔗 References (6)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22017
- patchhttps://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/windowsdesktop-whatsnew#updates-for-version-123130
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5013944
- referencehttps://support.microsoft.com/help/5013944
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5013943
- referencehttps://support.microsoft.com/help/5013943