CVE-2022-21849
published 2022-01-11CVE-2022-21849: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.24%
92.8th percentile
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19177 | 10.0.10240.19177 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.4886 | 10.0.14393.4886 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2452 | 10.0.17763.2452 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2452 | 10.0.17763.2452 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2037 | 10.0.18363.2037 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1466 | 10.0.19042.1466 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1466 | 10.0.19043.1466 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19043.1466 | 10.0.19043.1466 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.434 | 10.0.22000.434 |
| microsoft | windows_server | — | — |
| microsoft | windows_server | — | — |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.4886 | 10.0.14393.4886 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.2452 | 10.0.17763.2452 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.469 | 10.0.20348.469 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1466 | 10.0.19042.1466 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Check if the IKE and AuthIP IPsec Keying Modules service (Ikeext) is running — systems with this service active are vulnerable to CVE-2022-21849 exploitation ↗
- →Use PowerShell command 'Get-Service Ikeext' to enumerate whether the vulnerable IKE service is running on a host ↗
- →Use SC command 'sc query ikeext' to enumerate whether the vulnerable IKE service is running on a host ↗
- →Target systems are those with IKEv2 enabled; unauthenticated remote attackers can trigger multiple vulnerabilities when the IPSec service is running ↗
- ·Exploitation requires IKE version 2 to be enabled on the target system ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7gmw-8gxm-r73q: Windows IKE Extension Remote Code Execution Vulnerability
ghsa_unreviewed·2022-01-12
CVE-2022-21849 [CRITICAL] GHSA-7gmw-8gxm-r73q: Windows IKE Extension Remote Code Execution Vulnerability
Windows IKE Extension Remote Code Execution Vulnerability.
Microsoft
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
vendor_msrc·2022-01-11·CVSS 9.8
CVE-2022-21849 [CRITICAL] Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
In an environment where Internet Key Exchange (IKE) version 2 is enabled, a remote attacker could trigger multiple vulnerabilities without being authenticated.
Windows IKE Extension: Windows IKE Extension
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009557
Reference: https://support.microsoft.com/help/5009557
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009
No detection rules found.
No public exploits indexed.
Qualys
Microsoft & Adobe Patch Tuesday (January 2022) – Microsoft 126 Vulnerabilities with 9 Critical, Adobe 41 Vulnerabilities, 22 critical
blogs_qualys·2022-01-11·CVSS 9.0
[CRITICAL] Microsoft & Adobe Patch Tuesday (January 2022) – Microsoft 126 Vulnerabilities with 9 Critical, Adobe 41 Vulnerabilities, 22 critical
## Table of Contents
Microsoft Patch Tuesday January 2022
Adobe Patch Tuesday January 2022
Discover and Prioritize Patch Tuesday Vulnerabilities in VMDR
Respond by Patching
Patch Tuesday Dashboard
Webinar Series: This Month in Vulnerabilities and Patches
About Patch Tuesday
Contributor
## Microsoft Patch Tuesday – January 2022
Microsoft patched 126 vulnerabilities in their January 2022 Patch Tuesday release. Out of these, nine are rated as critical severity. As of this writing, none of the 126 vulnerabilities are known to be actively exploited.
Microsoft has fixed problems in their software including Remote Code Execution (RCE) vulnerabilities, privilege escalation security flaws, spoofing bugs, and Denial of Service (DoS) issues.
## Critical Microsoft Vulnerabilities Patched
Qualys
Microsoft & Adobe Patch Tuesday (January 2022) – Microsoft 126 Vulnerabilities with 9 Critical, Adobe 41 Vulnerabilities, 22 critical | Qualys
blogs_qualys·2022-01-11·CVSS 9.0
[CRITICAL] Microsoft & Adobe Patch Tuesday (January 2022) – Microsoft 126 Vulnerabilities with 9 Critical, Adobe 41 Vulnerabilities, 22 critical | Qualys
#### Table of Contents
- Microsoft Patch Tuesday January 2022
- Adobe Patch Tuesday January 2022
- Discover and Prioritize Patch Tuesday Vulnerabilities in VMDR
- Respond by Patching
- Patch Tuesday Dashboard
- Webinar Series: This Month in Vulnerabilities and Patches
- About Patch Tuesday
- Contributor
## Microsoft Patch Tuesday – January 2022
Microsoft patched 126 vulnerabilities in their January 2022 Patch Tuesday release. Out of these, nine are rated as critical severity. As of this writing, none of the 126 vulnerabilities are known to be actively exploited.
Microsoft has fixed problems in their software including Remote Code Execution (RCE) vulnerabilities, privilege escalation security flaws, spoofing bugs, and Denial of Service (DoS) issues.
### Critical Microsoft Vulnerabiliti
Crowdstrike
January 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] January 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2022-01-11
Published