CVE-2022-21974
published 2022-02-09CVE-2022-21974: Roaming Security Rights Management Services Remote Code Execution Vulnerability
PriorityP345high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
4.97%
91.2th percentile
Roaming Security Rights Management Services Remote Code Execution Vulnerability
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.4946 | 10.0.14393.4946 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2565 | 10.0.17763.2565 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2565 | 10.0.17763.2565 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2094 | 10.0.18363.2094 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1526 | 10.0.19042.1526 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1526 | 10.0.19043.1526 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1526 | 10.0.19044.1526 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.493 | 10.0.22000.493 |
| microsoft | windows_server | — | — |
| microsoft | windows_server | — | — |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.4946 | 10.0.14393.4946 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.2565 | 10.0.17763.2565 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.524 | 10.0.20348.524 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1526 | 10.0.19042.1526 |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3jrq-4wj8-868w: Roaming Security Rights Management Services Remote Code Execution Vulnerability
ghsa_unreviewed·2022-02-10
CVE-2022-21974 [HIGH] GHSA-3jrq-4wj8-868w: Roaming Security Rights Management Services Remote Code Execution Vulnerability
Roaming Security Rights Management Services Remote Code Execution Vulnerability.
Microsoft
Roaming Security Rights Management Services Remote Code Execution Vulnerability
vendor_msrc·2022-02-08·CVSS 7.8
CVE-2022-21974 [HIGH] Roaming Security Rights Management Services Remote Code Execution Vulnerability
Roaming Security Rights Management Services Remote Code Execution Vulnerability
FAQ: According to the CVSS score, the Attack Vector is Local. Why does the CVE title indicate that this is a Remote Code Execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution/"ACE". The attack itself is carried out locally.
An example scenario for a When the score indicates that the Attack Vector is Local and User Interaction is Required, that describes an exploit that an attacker, through social engineering, convinces a victim, for example, to go to a download and locally run a malicious file from a website or attached to an email which leads to a local attack on their computer.
FAQ: According to the CVSS metr
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-09
Published