CVE-2022-24500
published 2022-04-15CVE-2022-24500: Windows SMB Remote Code Execution Vulnerability Windows SMB Remote Code Execution Vulnerability
high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
38.05%
98.4th percentile
Windows SMB Remote Code Execution Vulnerability
Windows SMB Remote Code Execution Vulnerability
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19265 | 10.0.10240.19265 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5066 | 10.0.14393.5066 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2803 | 10.0.17763.2803 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2803 | 10.0.17763.2803 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2212 | 10.0.18363.2212 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1645 | 10.0.19042.1645 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1645 | 10.0.19043.1645 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1645 | 10.0.19044.1645 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.613 | 10.0.22000.613 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25924 | 6.1.7601.25924 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25924 | 6.1.7601.25924 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20337 | 6.3.9600.20337 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.25924 | 6.1.7601.25924 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21446 | 6.0.6003.21446 |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23679 | 6.2.9200.23679 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20337 | 6.3.9600.20337 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5066 | 10.0.14393.5066 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.2803 | 10.0.17763.2803 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.643 | 10.0.20348.643 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1645 | 10.0.19042.1645 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
| msrc | windows_10_version_20h2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for user connections to external or untrusted SMB servers, as exploitation requires a user to access a malicious SMB server as part of an OS API call. ↗
- →Watch for social engineering vectors (email or chat messages) containing links or UNC paths pointing to external SMB server shares, used to lure users into triggering the vulnerability. ↗
- ·Blocking TCP port 445 at the perimeter firewall mitigates Internet-based attacks but does NOT protect against exploitation originating from inside the local network. ↗
- ·Exploitation requires user interaction — a victim must be socially engineered into connecting to a malicious SMB server share; drive-by or unauthenticated wormable exploitation without user action is not the primary attack vector here. ↗
- ·At time of disclosure, exploit status was 'Exploitation Less Likely' for both latest and older software releases, and the vulnerability had not been publicly disclosed or exploited in the wild. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
cvelistv58.8HIGH
vulncheck8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CVEList
Windows SMB Remote Code Execution Vulnerability
cvelistv5·2022-04-15·CVSS 8.8
CVE-2022-24500 [HIGH] Windows SMB Remote Code Execution Vulnerability
Windows SMB Remote Code Execution Vulnerability
Windows SMB Remote Code Execution Vulnerability
VulnCheck
Windows SMB Remote Code Execution
vulncheck·2022·CVSS 8.8
CVE-2022-24500 [HIGH] Windows SMB Remote Code Execution
Windows SMB Remote Code Execution
Windows SMB Remote Code Execution Vulnerability
Affected: Microsoft Windows
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.group-ib.com/resources/research-hub/hi-tech-crime-trends-2022/
Microsoft
Windows SMB Remote Code Execution Vulnerability
vendor_msrc·2022-04-12·CVSS 8.8
CVE-2022-24500 [HIGH] Windows SMB Remote Code Execution Vulnerability
Windows SMB Remote Code Execution Vulnerability
FAQ: How could an attacker exploit the vulnerability?
For vulnerability to be exploited, a user would need to access a malicious SMB server to retrieve some data as part of an OS API call.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
This vulnerability requires that a user with an affected version of Windows access a malicious server. An attacker would have to host a specially crafted server share or website. An attacker would have no way to force users to visit this specially crafted server share or website, but would have to convince them to visit the server share or website, typically by way of an enticement in an email or chat message.
Windows SMB: Windows SMB
Micr
No detection rules found.
No public exploits indexed.
Checkpoint
30th May – Threat Intelligence Report
blogs_checkpoint·2022-05-30
CVE-2022-26833 30th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 30th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 30th May, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research reported how the Conti ransom group has taken cybercrime to a new, geopolitical level. They intervene in the internal politics of Costa Rica, the relationship between Costa Rica and the US, and basically moved the ransomware gangs to a new business stage of country extortion.
Check Point Harmony Endpoint and
Krebs
Microsoft Patch Tuesday, April 2022 Edition
blogs_krebs·2022-04-13·CVSS 9.8
CVE-2022-24521 [CRITICAL] Microsoft Patch Tuesday, April 2022 Edition
Microsoft on Tuesday released updates to fix roughly 120 security vulnerabilities in its Windows operating systems and other software. Two of the flaws have been publicly detailed prior to this week, and one is already seeing active exploitation, according to a report from the U.S. National Security Agency (NSA).
Of particular concern this month is CVE-2022-24521 , which is a “privilege escalation” vulnerability in the Windows common log file system driver. In its advisory, Microsoft said it received a report from the NSA that the flaw is under active attack.
“It’s not stated how widely the exploit is being used in the wild, but it’s likely still targeted at this point and not broadly available,” assessed Dustin Childs with Trend Micro’s Zero Day Initiative. “Go patch your systems before
Krebs
Microsoft Patch Tuesday, April 2022 Edition
blogs_krebs·2022-04-13·CVSS 9.8
CVE-2022-24521 [CRITICAL] Microsoft Patch Tuesday, April 2022 Edition
Microsoft on Tuesday released updates to fix roughly 120 security vulnerabilities in its Windows operating systems and other software. Two of the flaws have been publicly detailed prior to this week, and one is already seeing active exploitation, according to a report from the U.S. National Security Agency (NSA).
Of particular concern this month is CVE-2022-24521, which is a “privilege escalation” vulnerability in the Windows common log file system driver. In its advisory, Microsoft said it received a report from the NSA that the flaw is under active attack.
“It’s not stated how widely the exploit is being used in the wild, but it’s likely still targeted at this point and not broadly available,” assessed Dustin Childs with Trend Micro’s Zero Day Initiative. “Go patch your systems before
Qualys
April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical.
blogs_qualys·2022-04-12·CVSS 8.8
[HIGH] April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
Notable Microsoft Vulnerabilities Patched
Notable Adobe Vulnerabilities Patched
About Qualys Patch Tuesday
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Monthly Webinar Series: This Month in Vulnerabilities & Patches
Join the Webinar This Month in Vulnerabilities & Patches
Contributor
## Microsoft Patch Tuesday Summary
Microsoft has fixed 145 vulnerabilities, including 17 Microsoft Edge vulnerabilities, in the April 2022 update, with ten classified as critical as they allow Remote Code Execution (RCE). This month’s Patch Tuesday release includes fixes for two zero-day vulnerabilities as well, one known to be actively exploited ( CVE-2022-
Talos
Microsoft Patch Tuesday includes most vulnerabilities since Sept. 2020
blogs_talos·2022-04-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday includes most vulnerabilities since Sept. 2020
Microsoft released its latest security update Tuesday, disclosing more than 140 vulnerabilities across its array of products. This is a departure from past Patch Tuesdays this year, which have only featured a few dozen vulnerabilities, and is the largest amount of issues in a single Patch Tuesday since September 2020.
Ten of these vulnerabilities are considered to be “critical,” while three others are listed as being of “moderate” severity and the remainder are considered “important.” There are also nine vulnerabilities that were first found in the Chromium web browser but affect Microsoft Edge, since it’s a Chromium-based browser. Edge users do not need to take any action to patch for these issues.
Windows Hyper-V contains three of the critical vulnerabilities patched this month — CVE-2
Talos
Microsoft Patch Tuesday includes most vulnerabilities since Sept. 2020
blogs_talos·2022-04-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday includes most vulnerabilities since Sept. 2020
## Microsoft Patch Tuesday includes most vulnerabilities since Sept. 2020
Microsoft released its latest security update Tuesday, disclosing more than 140 vulnerabilities across its array of products. This is a departure from past Patch Tuesdays this year, which have only featured a few dozen vulnerabilities, and is the largest amount of issues in a single Patch Tuesday since September 2020 .
Ten of these vulnerabilities are considered to be “critical,” while three others are listed as being of “moderate” severity and the remainder are considered “important.” There are also nine vulnerabilities that were first found in the Chromium web browser but affect Microsoft Edge, since it’s a Chromium-based browser. Edge users do not need to take any action to patch for these issues.
Windows Hyper
Qualys
April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical. | Qualys
blogs_qualys·2022-04-12·CVSS 8.8
[HIGH] April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- Notable Microsoft Vulnerabilities Patched
- Notable Adobe Vulnerabilities Patched
- About Qualys Patch Tuesday
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Monthly Webinar Series: This Month in Vulnerabilities & Patches
- Join the Webinar This Month in Vulnerabilities & Patches
- Contributor
## Microsoft Patch Tuesday Summary
Microsoft has fixed 145 vulnerabilities, including 17 Microsoft Edge vulnerabilities, in the April 2022 update, with ten classified as critical as they allow Remote Code Execution (RCE). This month’s Patch Tuesday release includes fixes for two zero-day vulnerabilities as well, one known to be actively exploited
Crowdstrike
April 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] April 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2022-04-15
Published
Exploited in the wild