cbcvebase.
CVE-2022-22013
published 2022-05-10

CVE-2022-22013: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.27%
81.1th percentile
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.1929710.0.10240.19297
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.512510.0.14393.5125
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.292810.0.17763.2928
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.292810.0.17763.2928
microsoftwindows_10_version_1909>= 10.0.0 < 10.0.18363.227410.0.18363.2274
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.170610.0.19042.1706
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.170610.0.19043.1706
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19043.170610.0.19043.1706
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.67510.0.22000.675
microsoftwindows_7>= 6.1.0 < 6.1.7601.259546.1.7601.25954
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.259546.1.7601.25954
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.203716.3.9600.20371
microsoftwindows_server
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.259546.1.7601.25954
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.214816.0.6003.21481
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.237146.2.9200.23714

Detection & IOCsextracted from sources · hover to see the quote

  • ·CVE-2022-22013 affects Windows LDAP (Lightweight Directory Access Protocol) and enables Remote Code Execution. Per Microsoft, as of the advisory date, the vulnerability has NOT been publicly exploited and exploitation is rated 'Less Likely' for both latest and older software releases.
  • ·The affected component is Windows LDAP. No proof-of-concept code, hashes, network indicators, or attack-specific commands were present in any of the provided sources. No operational IOCs can be extracted.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.