CVE-2022-21973
published 2022-03-09CVE-2022-21973: Windows Media Center Update Denial of Service Vulnerability
PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.63%
45.9th percentile
Windows Media Center Update Denial of Service Vulnerability
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25898 | 6.1.7601.25898 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25898 | 6.1.7601.25898 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20303 | 6.3.9600.20303 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23645 | 6.2.9200.23645 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20303 | 6.3.9600.20303 |
| msrc | windows_7_for_32-bit_systems_service_pack_1 | — | — |
| msrc | windows_7_for_x64-based_systems_service_pack_1 | — | — |
| msrc | windows_8.1_for_32-bit_systems | — | — |
| msrc | windows_8.1_for_x64-based_systems | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
cisa5.3MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r298-475q-q8x5: Windows Media Center Update Denial of Service Vulnerability
ghsa_unreviewed·2022-03-10
CVE-2022-21973 [MEDIUM] GHSA-r298-475q-q8x5: Windows Media Center Update Denial of Service Vulnerability
Windows Media Center Update Denial of Service Vulnerability.
Microsoft
Windows Media Center Update Denial of Service Vulnerability
vendor_msrc·2022-03-08·CVSS 5.5
CVE-2022-21973 [MEDIUM] Windows Media Center Update Denial of Service Vulnerability
Windows Media Center Update Denial of Service Vulnerability
Windows Media: Windows Media
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5011552
Reference: https://support.microsoft.com/help/5011552
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5011529
Reference: https://support.microsoft.com/help/5011529
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5011564
Reference: https://support.microsoft.com/help/5011564
Reference: https://catalog.update.microsoft.com/v7/site/Search.a
CISA
VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
cisa·2022-03-07·CVSS 5.3
CVE-2021-21973 [MEDIUM] CWE-20 VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
Vulnerability: VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
Affected: VMware vCenter Server and Cloud Foundation
VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-21973
Remediation Due Date: 2022-03-21
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-09
Published