CVE-2022-22012
Published on: Not Yet Published
Last Modified on: 05/17/2022 09:05:00 PM UTC
Certain versions of Windows 10 from Microsoft contain the following vulnerability:
Windows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22013, CVE-2022-22014, CVE-2022-29128, CVE-2022-29129, CVE-2022-29130, CVE-2022-29131, CVE-2022-29137, CVE-2022-29139, CVE-2022-29141.
- CVE-2022-22012 has been assigned by
secur[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 9.3 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Security Update Guide - Microsoft Security Response Center | portal.msrc.microsoft.com text/html |
![]() |
Related QID Numbers
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Microsoft | Windows 10 | - | All | All | All |
Operating System | Microsoft | Windows 10 | - | All | All | All |
Operating System | Microsoft | Windows 10 | 1607 | All | All | All |
Operating System | Microsoft | Windows 10 | 1607 | All | All | All |
Operating System | Microsoft | Windows 10 | 1809 | All | All | All |
Operating System | Microsoft | Windows 10 | 1809 | All | All | All |
Operating System | Microsoft | Windows 10 | 1809 | All | All | All |
Operating System | Microsoft | Windows 10 | 1909 | All | All | All |
Operating System | Microsoft | Windows 10 | 1909 | All | All | All |
Operating System | Microsoft | Windows 10 | 1909 | All | All | All |
Operating System | Microsoft | Windows 10 | 20h2 | All | All | All |
Operating System | Microsoft | Windows 10 | 20h2 | All | All | All |
Operating System | Microsoft | Windows 10 | 20h2 | All | All | All |
Operating System | Microsoft | Windows 10 | 21h1 | All | All | All |
Operating System | Microsoft | Windows 10 | 21h1 | All | All | All |
Operating System | Microsoft | Windows 10 | 21h1 | All | All | All |
Operating System | Microsoft | Windows 10 | 21h2 | All | All | All |
Operating System | Microsoft | Windows 10 | 21h2 | All | All | All |
Operating System | Microsoft | Windows 10 | 21h2 | All | All | All |
Operating System | Microsoft | Windows 11 | - | All | All | All |
Operating System | Microsoft | Windows 11 | - | All | All | All |
Operating System | Microsoft | Windows 7 | - | sp1 | All | All |
Operating System | Microsoft | Windows 7 | - | sp1 | All | All |
Operating System | Microsoft | Windows 8.1 | - | All | All | All |
Operating System | Microsoft | Windows 8.1 | - | All | All | All |
Operating System | Microsoft | Windows Server | 2022 | All | All | All |
Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
Operating System | Microsoft | Windows Server 2008 | sp2 | All | All | All |
Operating System | Microsoft | Windows Server 2008 | sp2 | All | All | All |
Operating System | Microsoft | Windows Server 2012 | - | All | All | All |
Operating System | Microsoft | Windows Server 2012 | r2 | All | All | All |
Operating System | Microsoft | Windows Server 2016 | - | All | All | All |
Operating System | Microsoft | Windows Server 2019 | - | All | All | All |
- cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x64:*:
- cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x86:*:
- cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:x64:*:
- cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:x86:*:
- cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:arm64:*:
- cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:x64:*:
- cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:x86:*:
- cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:arm64:*:
- cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:x64:*:
- cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:x86:*:
- cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:arm64:*:
- cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:x64:*:
- cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:x86:*:
- cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:arm64:*:
- cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:x64:*:
- cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:x86:*:
- cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:arm64:*:
- cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:x64:*:
- cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:x86:*:
- cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:arm64:*:
- cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:x64:*:
- cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:x64:*:
- cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:x86:*:
- cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:x64:*:
- cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:x86:*:
- cpe:2.3:o:microsoft:windows_server:2022:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*:
- cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x86:*:
- cpe:2.3:o:microsoft:windows_server_2008:sp2:*:*:*:*:*:x64:*:
- cpe:2.3:o:microsoft:windows_server_2008:sp2:*:*:*:*:*:x86:*:
- cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-22012 Windows LDAP Remote Code Execution Vulnerability CVSS 9.8 CVE-2022-26925 Windows LSA Spoofing Vulne… twitter.com/i/web/status/1… | 2022-05-10 19:42:42 |
![]() |
CVE-2022-29128 : #Windows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-… twitter.com/i/web/status/1… | 2022-05-10 21:00:17 |
![]() |
CVE-2022-29129 : #Windows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-… twitter.com/i/web/status/1… | 2022-05-10 21:00:41 |
![]() |
CVE-2022-29130 : #Windows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-… twitter.com/i/web/status/1… | 2022-05-10 21:01:02 |
![]() |
CVE-2022-29131 : #Windows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-… twitter.com/i/web/status/1… | 2022-05-10 21:01:28 |
![]() |
CVE-2022-29137 : #Windows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-… twitter.com/i/web/status/1… | 2022-05-10 21:03:19 |
![]() |
CVE-2022-29139 : #Windows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-… twitter.com/i/web/status/1… | 2022-05-10 21:04:16 |
![]() |
CVE-2022-29141 : #Windows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-… twitter.com/i/web/status/1… | 2022-05-10 21:05:05 |
![]() |
If you want to check vulnerability to CVE-2022-22012 (RCE in LDAP on Domain Controllers). You still want to patch,… twitter.com/i/web/status/1… | 2022-05-10 21:24:31 |
![]() |
③認証やユーザーの操作なしで悪用が可能なため要注意は3件。悪用には前提条件ありなので該当環境を要確認 CVE-2022-22012/CVE-2022-29130 (Windows LDAP) (MaxReceiveBufferを… twitter.com/i/web/status/1… | 2022-05-11 00:29:35 |
![]() |
#windowsupdate #microsoft CVSS 基本値が 9.8 と高いスコアで認証やユーザの操作なしで悪用が可能な脆弱性 3 件. CVE-2022-22012 Windows LDAP CVE-2022-291… twitter.com/i/web/status/1… | 2022-05-11 00:37:01 |
![]() |
[Vuln] We have just added an important vulnerability affecting Microsoft Windows (CVE-2022-22012) vuldb.com/?id.199355 | 2022-05-11 04:13:06 |