cbcvebase.
CVE-2022-24500
published 2022-04-15

CVE-2022-24500: Windows SMB Remote Code Execution Vulnerability Windows SMB Remote Code Execution Vulnerability

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
38.05%
98.4th percentile
Windows SMB Remote Code Execution Vulnerability Windows SMB Remote Code Execution Vulnerability

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.1926510.0.10240.19265
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.506610.0.14393.5066
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.280310.0.17763.2803
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.280310.0.17763.2803
microsoftwindows_10_version_1909>= 10.0.0 < 10.0.18363.221210.0.18363.2212
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.164510.0.19042.1645
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.164510.0.19043.1645
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.164510.0.19044.1645
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.61310.0.22000.613
microsoftwindows_7>= 6.1.0 < 6.1.7601.259246.1.7601.25924
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.259246.1.7601.25924
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.203376.3.9600.20337
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.259246.1.7601.25924
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.214466.0.6003.21446
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.236796.2.9200.23679
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.203376.3.9600.20337
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.506610.0.14393.5066
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.280310.0.17763.2803
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.64310.0.20348.643
microsoftwindows_server_version_20h2>= 10.0.0 < 10.0.19042.164510.0.19042.1645
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1809
msrcwindows_10_version_1909
msrcwindows_10_version_20h2

Detection & IOCsextracted from sources · hover to see the quote

portTCP/445
  • Monitor for user connections to external or untrusted SMB servers, as exploitation requires a user to access a malicious SMB server as part of an OS API call.
  • Watch for social engineering vectors (email or chat messages) containing links or UNC paths pointing to external SMB server shares, used to lure users into triggering the vulnerability.
  • ·Blocking TCP port 445 at the perimeter firewall mitigates Internet-based attacks but does NOT protect against exploitation originating from inside the local network.
  • ·Exploitation requires user interaction — a victim must be socially engineered into connecting to a malicious SMB server share; drive-by or unauthenticated wormable exploitation without user action is not the primary attack vector here.
  • ·At time of disclosure, exploit status was 'Exploitation Less Likely' for both latest and older software releases, and the vulnerability had not been publicly disclosed or exploited in the wild.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
cvelistv58.8HIGH
vulncheck8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.