CVE-2022-23294HighCVSS 8.8

Windows Event Tracing Remote Code Execution Vulnerability

Published
March 8, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How can an attacker exploit this vulnerability? An authenticated attacker could potentially take advantage of this vulnerability to execute malicious code through the Event Log's Remote Procedure Call (RPC) endpoint on the server-side.

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Any authenticated user could trigger this vulnerability. It does not require admin or other elevated privileges.

What is a Remote Procedure Call? Remote Procedure Call (RPC) is a communication mechanism that allows computers to communicate with one another over a network. An RPC consists of a procedure identifier, parameters passed to the procedure, and a value returned to the caller (client computer) after the procedure has executed on the remote system (server computer). See Remote procedure call (RPC) for more information.

🎯 Affected products34

  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 Version 1607 for x64-based Systems
  • Windows 10 Version 1809 for 32-bit Systems
  • Windows 10 Version 1809 for ARM64-based Systems
  • Windows 10 Version 1809 for x64-based Systems
  • Windows 10 Version 1909 for 32-bit Systems
  • Windows 10 Version 1909 for ARM64-based Systems
  • Windows 10 Version 1909 for x64-based Systems
  • Windows 10 Version 20H2 for 32-bit Systems
  • Windows 10 Version 20H2 for ARM64-based Systems
  • Windows 10 Version 21H1 for 32-bit Systems
  • Windows 10 Version 21H1 for ARM64-based Systems
  • Windows 10 Version 21H1 for x64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 10 for 32-bit Systems
  • Windows 10 for x64-based Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows 8.1 for 32-bit systems
  • Windows 8.1 for x64-based systems
  • Windows RT 8.1
  • Windows Server 2012
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2019
  • +4 more not shown

✅ Remediation

KB5011503 (Security Update) — fixed build 10.0.17763.2686 KB5011485 (Security Update) — fixed build 10.0.18363.2158 KB5011487 (Security Update) — fixed build 10.0.19043.1586 KB5011497 (Security Update) — fixed build 10.0.20348.587 KB5011580 (Security Hotpatch Update) — fixed build 10.0.20348.580 KB5011487 (Security Update) — fixed build 10.0.19042.1586 KB5011493 (Security Update) — fixed build 10.0.22000.556 KB5011487 (Security Update) — fixed build 10.0.19044.1586 KB5011491 (Security Update) — fixed build 10.0.10240.19235 KB5011495 (Security Update) — fixed build 10.0.14393.5006 KB5011564 (Monthly Rollup) — fixed build 6.3.9600.20303 KB5011560 (Security Only) — fixed build 6.3.9600.20303 KB5011564 (Monthly Rollup) — fixed build 6.3.9600.20296 KB5011535 (Monthly Rollup) — fixed build 6.2.9200.23645 KB5011527 (Security Only) — fixed build 6.2.9200.23639

🔗 References (25)