DiskUsage.exe Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? This vulnerability requires that a user with an affected version of Windows access a malicious server. An attacker would have to host a specially crafted server share or website. An attacker would have no way to force users to visit this specially crafted server share or website, but would have to convince them to visit the server share or website, typically by way of an enticement in an email or chat message.
🎯 Affected products4
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
✅ Remediation
KB5012604 (Security Update) — fixed build 10.0.20348.643 KB5012592 (Security Update) — fixed build 10.0.22000.613
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26830
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5012604
- referencehttps://support.microsoft.com/help/5012604
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5012592
- referencehttps://support.microsoft.com/help/5012592