CVE-2022-26809
published 2022-04-15CVE-2022-26809: Remote Procedure Call Runtime Remote Code Execution Vulnerability
PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
91.32%
99.8th percentile
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19265 | 10.0.10240.19265 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5066 | 10.0.14393.5066 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2803 | 10.0.17763.2803 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2803 | 10.0.17763.2803 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2212 | 10.0.18363.2212 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1645 | 10.0.19042.1645 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1645 | 10.0.19043.1645 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1645 | 10.0.19044.1645 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.613 | 10.0.22000.613 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25924 | 6.1.7601.25924 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25924 | 6.1.7601.25924 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20337 | 6.3.9600.20337 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.25924 | 6.1.7601.25924 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21446 | 6.0.6003.21446 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23679 | 6.2.9200.23679 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20337 | 6.3.9600.20337 |
| microsoft | windows_server_2016 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for specially crafted RPC calls sent to RPC hosts from unauthenticated remote sources; exploitation results in remote code execution with RPC service permissions. ↗
- →The known PoC exploit targets the vulnerable function OSF_SCALL::GetCoalescedBuffer via a modified RPC pipe type defined in an IDL file; detect anomalous RPC pipe-type usage or unexpected MIDL-compiled interfaces. ↗
- →The PoC uses impacket's dcerpc/rpcrt library to send crafted packets; detect use of impacket RPC tooling (impacket.dcerpc.v5.rpcrt) against Windows RPC endpoints. ↗
- →Block TCP port 445 at the enterprise perimeter firewall as a mitigation; the original researcher used SMB as the attack vector to trigger the exploit in the RPC service. ↗
- →This is a zero-click vulnerability — no user interaction required; alert on inbound unauthenticated RPC connections from external/internet-facing sources, especially to Windows SMB service. ↗
- ·Blocking TCP 445/139 (SMB) at the perimeter does NOT fully protect against all attack vectors for this vulnerability, since the flaw is in RPC, not SMB. The SMB vector was only the one demonstrated to Microsoft by the submitting researcher. ↗
- ·The public PoC (published May 1, 2022 on GitHub) only works against a customized RPC server and requires specific server-side settings; it is not a ready-made exploit for default Windows services but could be adapted. ↗
- ·The threat is not limited to the Windows SMB service; other services using the vulnerable RPC component are also potentially affected. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
vendor_msrc9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7c4p-f5qf-vx4w: Remote Procedure Call Runtime Remote Code Execution Vulnerability
ghsa_unreviewed·2022-04-16·CVSS 8.8
CVE-2022-24492 [HIGH] GHSA-7c4p-f5qf-vx4w: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-24528, CVE-2022-26809.
GHSA
GHSA-j878-9p76-8q9h: Remote Procedure Call Runtime Remote Code Execution Vulnerability
ghsa_unreviewed·2022-04-16·CVSS 8.8
CVE-2022-24528 [HIGH] GHSA-j878-9p76-8q9h: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-24492, CVE-2022-26809.
GHSA
GHSA-q2wc-9mx8-xr8j: Remote Procedure Call Runtime Remote Code Execution Vulnerability
ghsa_unreviewed·2022-04-16·CVSS 8.8
CVE-2022-26809 [HIGH] GHSA-q2wc-9mx8-xr8j: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-24492, CVE-2022-24528.
VulnCheck
Microsoft Windows CLFS Driver Privilege Escalation Vulnerability
vulncheck·2022·CVSS 7.8
CVE-2022-24521 [HIGH] CWE-787 Microsoft Windows CLFS Driver Privilege Escalation Vulnerability
Microsoft Windows CLFS Driver Privilege Escalation Vulnerability
Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2022-Apr; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.covertswarm.com/post/multiple-windows-zero-days-cve-2022-24521-cve-2022-26904-and-cve-2022-26809; https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius/; https://www.bleepingcomputer.com/news/se
VulnCheck
Remote Procedure Call Runtime Remote Code Execution
vulncheck·2022·CVSS 9.8
CVE-2022-26809 [CRITICAL] Remote Procedure Call Runtime Remote Code Execution
Remote Procedure Call Runtime Remote Code Execution
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Affected: Microsoft Windows
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.covertswarm.com/post/multiple-windows-zero-days-cve-2022-24521-cve-2022-26904-and-cve-2022-26809; https://www.group-ib.com/resources/research-hub/hi-tech-crime-trends-2022/
Exploit PoC: https://vulncheck.com/xdb/bc623cfe5572
VulnCheck
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
vulncheck·2022·CVSS 7.0
CVE-2022-26904 [HIGH] CWE-362 Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.covertswarm.com/post/multiple-windows-zero-days-cve-2022-24521-cve-2022-26904-and-cve-2022-26809; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-05-16
Microsoft
Remote Procedure Call Runtime Remote Code Execution Vulnerability
vendor_msrc·2022-04-12·CVSS 9.8
CVE-2022-26809 [CRITICAL] Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
To exploit this vulnerability, an unauthenticated attacker would need to send a specially crafted RPC call to an RPC host. This could result in remote code execution on the server side with the same permissions as the RPC service.
FAQ: Why did Microsoft remove the Mitigation to “Block TCP port 445 at the enterprise perimeter firewall”?
The researcher who submitted the vulnerability used SMB as the attack vector to trigger the exploit in the RPC service, so the mitigation was effective for the issue that was presented to us. Although blocking ports 139 and 445 [SMB] at the perimeter firewall is a recommended practice, it does not directly protect against all potential a
No detection rules found.
No public exploits indexed.
Securelist
IT threat evolution in Q2 2022. Non-mobile statistics
blogs_securelist·2022-08-15
IT threat evolution in Q2 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
TOP 10 countries and territories that serve as sources of web-based attacks
Countries and territories where users faced the greatest risk of online infection
Local threat
Securelist
Non-mobile malware statistics, Q2 2022
blogs_securelist·2022-08-15
Non-mobile malware statistics, Q2 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q2 2022
- IT threat evolution in Q2 2022. Non-mobile statistics
- IT threat evolution in Q2 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q2 2022:
- Kaspersky solutions blocked 1,164,544,060 attacks from online resources across the globe.
- Web Anti-Virus recognized 273,033,368 unique URLs as malicious. Attempts to run malware fo
Unit42
Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
blogs_unit42·2022-07-27·CVSS 9.8
CVE-2022-26809 [CRITICAL] Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
Chao Lei
Tao Yan
Haozhe Zhang
Qi Deng
Published: July 27, 2022
High Profile Threats
Vulnerabilities
CVE-2022-26809
CVE-2022-26923
CVE-2022-26925
Microsoft
Microsoft Windows
## Executive Summary
Microsoft introduced patches for several critical vulnerabilities in their April and May 2022 security updates, including the following vulnerabilities:
CVE-2022-26809 : An unauthorized attacker can exploit this vulnerability by sending a specially crafted Remote Procedure Call (RPC) to remotely execute arbitrary code on the vulnerable device.
CVE-2022-26923 : A low-privileged user can escalate privilege to a domain ad
Unit42
Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
blogs_unit42·2022-07-27·CVSS 9.8
CVE-2022-26925 [CRITICAL] Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
## Executive Summary
Microsoft introduced patches for several critical vulnerabilities in their April and May 2022 security updates, including the following vulnerabilities:
- CVE-2022-26809: An unauthorized attacker can exploit this vulnerability by sending a specially crafted Remote Procedure Call (RPC) to remotely execute arbitrary code on the vulnerable device.
- CVE-2022-26923: A low-privileged user can escalate privilege to a domain administrator in a default Active Directory environment with the “Active Directory Certificate Services” server role installed.
- CVE-2022-26925: Unauthenticated attackers can remotely exploit and force domain controllers to authenticate them via the Windows NT LAN Manager (NTLM) security protocol.
We highly recommend that customers apply these securit
Tenable
Cybersecurity Snapshot: 6 Things That Matter Right Now
blogs_tenable·2022-06-17
Cybersecurity Snapshot: 6 Things That Matter Right Now
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
So Many CVEs, So Little Time: Zero In and ‘Zero Click’ into the Current Vulnerability Landscape
blogs_tenable·2022-06-08
So Many CVEs, So Little Time: Zero In and ‘Zero Click’ into the Current Vulnerability Landscape
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
30th May – Threat Intelligence Report
blogs_checkpoint·2022-05-30
CVE-2022-26833 30th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 30th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 30th May, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research reported how the Conti ransom group has taken cybercrime to a new, geopolitical level. They intervene in the internal politics of Costa Rica, the relationship between Costa Rica and the US, and basically moved the ransomware gangs to a new business stage of country extortion.
Check Point Harmony Endpoint and
Krebs
Microsoft Patch Tuesday, April 2022 Edition
blogs_krebs·2022-04-13·CVSS 9.8
CVE-2022-24521 [CRITICAL] Microsoft Patch Tuesday, April 2022 Edition
Microsoft on Tuesday released updates to fix roughly 120 security vulnerabilities in its Windows operating systems and other software. Two of the flaws have been publicly detailed prior to this week, and one is already seeing active exploitation, according to a report from the U.S. National Security Agency (NSA).
Of particular concern this month is CVE-2022-24521 , which is a “privilege escalation” vulnerability in the Windows common log file system driver. In its advisory, Microsoft said it received a report from the NSA that the flaw is under active attack.
“It’s not stated how widely the exploit is being used in the wild, but it’s likely still targeted at this point and not broadly available,” assessed Dustin Childs with Trend Micro’s Zero Day Initiative. “Go patch your systems before
Krebs
Microsoft Patch Tuesday, April 2022 Edition
blogs_krebs·2022-04-13·CVSS 9.8
CVE-2022-24521 [CRITICAL] Microsoft Patch Tuesday, April 2022 Edition
Microsoft on Tuesday released updates to fix roughly 120 security vulnerabilities in its Windows operating systems and other software. Two of the flaws have been publicly detailed prior to this week, and one is already seeing active exploitation, according to a report from the U.S. National Security Agency (NSA).
Of particular concern this month is CVE-2022-24521, which is a “privilege escalation” vulnerability in the Windows common log file system driver. In its advisory, Microsoft said it received a report from the NSA that the flaw is under active attack.
“It’s not stated how widely the exploit is being used in the wild, but it’s likely still targeted at this point and not broadly available,” assessed Dustin Childs with Trend Micro’s Zero Day Initiative. “Go patch your systems before
Qualys
April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical.
blogs_qualys·2022-04-12·CVSS 8.8
[HIGH] April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
Notable Microsoft Vulnerabilities Patched
Notable Adobe Vulnerabilities Patched
About Qualys Patch Tuesday
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Monthly Webinar Series: This Month in Vulnerabilities & Patches
Join the Webinar This Month in Vulnerabilities & Patches
Contributor
## Microsoft Patch Tuesday Summary
Microsoft has fixed 145 vulnerabilities, including 17 Microsoft Edge vulnerabilities, in the April 2022 update, with ten classified as critical as they allow Remote Code Execution (RCE). This month’s Patch Tuesday release includes fixes for two zero-day vulnerabilities as well, one known to be actively exploited ( CVE-2022-
Tenable
Microsoft’s April 2022 Patch Tuesday Addresses 117 CVEs (CVE-2022-24521)
blogs_tenable·2022-04-12·CVSS 7.8
[HIGH] Microsoft’s April 2022 Patch Tuesday Addresses 117 CVEs (CVE-2022-24521)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical. | Qualys
blogs_qualys·2022-04-12·CVSS 8.8
[HIGH] April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- Notable Microsoft Vulnerabilities Patched
- Notable Adobe Vulnerabilities Patched
- About Qualys Patch Tuesday
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Monthly Webinar Series: This Month in Vulnerabilities & Patches
- Join the Webinar This Month in Vulnerabilities & Patches
- Contributor
## Microsoft Patch Tuesday Summary
Microsoft has fixed 145 vulnerabilities, including 17 Microsoft Edge vulnerabilities, in the April 2022 update, with ten classified as critical as they allow Remote Code Execution (RCE). This month’s Patch Tuesday release includes fixes for two zero-day vulnerabilities as well, one known to be actively exploited
Crowdstrike
April 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] April 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
arXiv
Beyond the Surface: Investigating Malicious CVE Proof of Concept Exploits on GitHub
arxiv_fulltext·2023-06-07
Beyond the Surface: Investigating Malicious CVE Proof of Concept Exploits on GitHub
Beyond the Surface: Investigating Malicious CVE Proof of Concept Exploits on GitHub
Soufian El Yadmani, Robin The, Olga Gadyatskaya
Leiden Institute of Advanced Computer Science, Leiden University
## Abstract
\
Exploit proof-of-concepts (PoCs) for known vulnerabilities are widely shared in the security community. They help security analysts to learn from each other and they facilitate security assessments and red teaming tasks. In the recent years, PoCs have been widely distributed, e.g., via dedicated websites and platforms, and public code repositories such as GitHub. However, there is no guarantee that PoCs in public code repositories come from trustworthy sources or even that they do what they are supposed to do.
In this work we investigate GitHub-hosted PoCs for known vulnerabili
2022-04-15
Published
Exploited in the wild