CVE-2022-23257
published 2022-04-15CVE-2022-23257: Windows Hyper-V Remote Code Execution Vulnerability
PriorityP348high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.60%
44.7th percentile
Windows Hyper-V Remote Code Execution Vulnerability
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1645 | 10.0.19043.1645 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1645 | 10.0.19044.1645 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.613 | 10.0.22000.613 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.1413 | 10.0.22621.1413 |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.643 | 10.0.20348.643 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1645 | 10.0.19042.1645 |
| msrc | windows_10_version_21h1_for_x64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_22h2_for_x64-based_systems | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_version_20h2 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4hw3-x9c6-9f43: Windows Hyper-V Remote Code Execution Vulnerability
ghsa_unreviewed·2022-04-16·CVSS 7.8
CVE-2022-24537 [HIGH] CWE-362 GHSA-4hw3-x9c6-9f43: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22008, CVE-2022-22009, CVE-2022-23257.
GHSA
GHSA-3pw7-m4qj-fpv2: Windows Hyper-V Remote Code Execution Vulnerability
ghsa_unreviewed·2022-04-16·CVSS 7.8
CVE-2022-22009 [HIGH] GHSA-3pw7-m4qj-fpv2: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22008, CVE-2022-23257, CVE-2022-24537.
GHSA
GHSA-f26q-x9wv-632w: Windows Hyper-V Remote Code Execution Vulnerability
ghsa_unreviewed·2022-04-16·CVSS 7.8
CVE-2022-22008 [HIGH] CWE-362 GHSA-f26q-x9wv-632w: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22009, CVE-2022-23257, CVE-2022-24537.
GHSA
GHSA-hr7f-gcqx-fq4v: Windows Hyper-V Remote Code Execution Vulnerability
ghsa_unreviewed·2022-04-16·CVSS 7.8
CVE-2022-23257 [HIGH] GHSA-hr7f-gcqx-fq4v: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22008, CVE-2022-22009, CVE-2022-24537.
Microsoft
Windows Hyper-V Remote Code Execution Vulnerability
vendor_msrc·2022-04-12·CVSS 8.8
CVE-2022-23257 [HIGH] Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally.
For example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on their computer.
FAQ: How could an attacker exploit this vulnerability?
To exploit this vulnerability, an attacker co
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday includes most vulnerabilities since Sept. 2020
blogs_talos·2022-04-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday includes most vulnerabilities since Sept. 2020
Microsoft released its latest security update Tuesday, disclosing more than 140 vulnerabilities across its array of products. This is a departure from past Patch Tuesdays this year, which have only featured a few dozen vulnerabilities, and is the largest amount of issues in a single Patch Tuesday since September 2020.
Ten of these vulnerabilities are considered to be “critical,” while three others are listed as being of “moderate” severity and the remainder are considered “important.” There are also nine vulnerabilities that were first found in the Chromium web browser but affect Microsoft Edge, since it’s a Chromium-based browser. Edge users do not need to take any action to patch for these issues.
Windows Hyper-V contains three of the critical vulnerabilities patched this month — CVE-2
Talos
Microsoft Patch Tuesday includes most vulnerabilities since Sept. 2020
blogs_talos·2022-04-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday includes most vulnerabilities since Sept. 2020
## Microsoft Patch Tuesday includes most vulnerabilities since Sept. 2020
Microsoft released its latest security update Tuesday, disclosing more than 140 vulnerabilities across its array of products. This is a departure from past Patch Tuesdays this year, which have only featured a few dozen vulnerabilities, and is the largest amount of issues in a single Patch Tuesday since September 2020 .
Ten of these vulnerabilities are considered to be “critical,” while three others are listed as being of “moderate” severity and the remainder are considered “important.” There are also nine vulnerabilities that were first found in the Chromium web browser but affect Microsoft Edge, since it’s a Chromium-based browser. Edge users do not need to take any action to patch for these issues.
Windows Hyper
Crowdstrike
April 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] April 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2022-04-15
Published