cbcvebase.
CVE-2022-23285
published 2022-03-09

CVE-2022-23285: Remote Desktop Client Remote Code Execution Vulnerability

PriorityP263high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
25.71%
97.7th percentile
Remote Desktop Client Remote Code Execution Vulnerability

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.1923510.0.10240.19235
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.500610.0.14393.5006
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.268610.0.17763.2686
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.268610.0.17763.2686
microsoftwindows_10_version_1909>= 10.0.0 < 10.0.18363.215810.0.18363.2158
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.158610.0.19042.1586
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.158610.0.19043.1586
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.158610.0.19044.1586
microsoftwindows_7>= 6.1.0 < 6.1.7601.258986.1.7601.25898
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.258986.1.7601.25898
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.203036.3.9600.20303
microsoftwindows_server
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.258986.1.7601.25898
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.236456.2.9200.23645
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.203036.3.9600.20303
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.500610.0.14393.5006
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.268610.0.17763.2686

Detection & IOCsextracted from sources · hover to see the quote

  • Exploitation vector: attacker must control a malicious Remote Desktop Server; victim initiates RDP connection to the attacker-controlled server with a vulnerable RDP client — monitor for outbound RDP connections to untrusted/external hosts
  • Exploitation assessed as 'More Likely' for both latest and older software releases — prioritize detection and patching of RDP client on all supported Windows versions
  • Affected component is Windows Remote Desktop Client (mstsc.exe / Remote Desktop client stack); focus endpoint monitoring on the RDP client process for anomalous post-connection behaviour
  • ·CVE-2022-23285 is server-side-attacker / client-side-victim: exploitation requires the victim to connect TO a malicious RDP server — not an inbound attack against an RDP server. Defensive controls should focus on restricting outbound RDP (TCP 3389) to trusted hosts only.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.