CVE-2022-41044CriticalCVSS 8.1
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition.
How could an attacker exploit this vulnerability? An unauthenticated attacker could send a specially crafted protocol message to a Routing and Remote Access Service (RRAS) server, which could lead to remote code execution (RCE) on the RAS server machine.
🎯 Affected products8
- Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
✅ Remediation
KB5020000 (Monthly Rollup) — fixed build 6.1.7601.26221 KB5020013 (Security Only) — fixed build 6.1.7601.26221 KB5020019 (Monthly Rollup) — fixed build 6.0.6003.21768 KB5020005 (Security Only) — fixed build 6.0.6003.21768
🔗 References (9)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41044
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5020000
- referencehttps://support.microsoft.com/help/5020000
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5020013
- referencehttps://support.microsoft.com/help/5020013
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5020019
- referencehttps://support.microsoft.com/help/5020019
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5020005
- referencehttps://support.microsoft.com/help/5020005