QID 377824
Date Published: 2022-12-14
QID 377824: Windows Terminal Remote Code Execution (RCE) Vulnerability
Windows Terminal is a multi-tabbed terminal emulator that Microsoft has developed. It can run any command-line app in a separate tab. It is preconfigured to run Command Prompt, PowerShell, WSL, SSH, and Azure Cloud Shell Connector.
Affected Versions:
Windows Terminal for Windows 10 below 1.15.2874
Windows Terminal for Windows 11 below 1.15.2875
QID Detection Logic (Authenticated):
The QID checks for vulnerable version of Windows Terminal by checking the file version of wt.exe.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code on the target system.
Solution
Microsoft has released patch, customers are advised to refer to KB5019758 for information pertaining to this vulnerability.
Vendor References
- CVE-2022-41079 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41079 - CVE-2022-41080 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41080 - CVE-2022-41123 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-44702 - CVE-2022-44702 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41078
CVEs related to QID 377824
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-44702 |
|