CVE-2022-22040
published 2022-07-12CVE-2022-22040: Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
PriorityP335high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
1.41%
69.7th percentile
Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19360 | 10.0.10240.19360 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5246 | 10.0.14393.5246 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3165 | 10.0.17763.3165 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3165 | 10.0.17763.3165 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1826 | 10.0.19042.1826 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1826 | 10.0.19043.1826 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1826 | 10.0.19044.1826 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.795 | 10.0.22000.795 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.26022 | 6.1.7601.26022 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.26022 | 6.1.7601.26022 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20478 | 6.3.9600.20478 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26022 | 6.1.7601.26022 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21569 | 6.0.6003.21569 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23771 | 6.2.9200.23771 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20478 | 6.3.9600.20478 |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5246 | 10.0.14393.5246 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.3165 | 10.0.17763.3165 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8fp6-xwm6-hv42: Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
ghsa_unreviewed·2022-07-13
CVE-2022-22040 [HIGH] CWE-400 GHSA-8fp6-xwm6-hv42: Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
Internet Information Services Dynamic Compression Module Denial of Service Vulnerability.
Microsoft
Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
vendor_msrc·2022-07-12·CVSS 7.3
CVE-2022-22040 [HIGH] Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to minor loss of confidentiality (C:L), integrity (I:L) and availability (A:L). What does that mean for this vulnerability?
While we cannot rule out the impact to Confidentiality, Integrity, and Availability, the ability to exploit this vulnerability by itself is limited. An attacker can force a bad response to be cached into a regular URL by having multiple occurrences of the same variable in the query string. The impact depends on the business logic of the user application.
Windows IIS: Windows IIS
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disc
VMware
VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2021-22040, CVE-2021-22041, CVE-2021-22042, CVE-2021-22043, CVE-2021-22050)
vendor_vmware·2022-02-15·CVSS 6.7
CVE-2021-22040 [MEDIUM] VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2021-22040, CVE-2021-22041, CVE-2021-22042, CVE-2021-22043, CVE-2021-22050)
VMSA-2022-0004: VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2021-22040, CVE-2021-22041, CVE-2021-22042, CVE-2021-22043, CVE-2021-22050)
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller.VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.4.
CVEs: CVE-2021-22040, CVE-2021-22041, CVE-2021-22042, CVE-2021-22043, CVE-2021-22050
Affected products: Fusion Pro, VMware Cloud Foundation, VMware ESXi, VMware Fusion, VMware Workstation, VMware vSphere, Workstation Player, Workstation Pro
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-12
Published