CVE-2022-26830
published 2022-04-15CVE-2022-26830: DiskUsage.exe Remote Code Execution Vulnerability DiskUsage.exe Remote Code Execution Vulnerability
high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
1.65%
73.8th percentile
DiskUsage.exe Remote Code Execution Vulnerability
DiskUsage.exe Remote Code Execution Vulnerability
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.613 | 10.0.22000.613 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.643 | 10.0.20348.643 |
| msrc | windows_11_version_21h2_for_arm64-based_systems | — | — |
| msrc | windows_11_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_server_2022 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
cvelistv57.5HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rrx6-pgjg-pmv7: DiskUsage
ghsa_unreviewed·2022-04-16
CVE-2022-26830 [HIGH] GHSA-rrx6-pgjg-pmv7: DiskUsage
DiskUsage.exe Remote Code Execution Vulnerability.
CVEList
DiskUsage.exe Remote Code Execution Vulnerability
cvelistv5·2022-04-15·CVSS 7.5
CVE-2022-26830 [HIGH] DiskUsage.exe Remote Code Execution Vulnerability
DiskUsage.exe Remote Code Execution Vulnerability
DiskUsage.exe Remote Code Execution Vulnerability
Microsoft
DiskUsage.exe Remote Code Execution Vulnerability
vendor_msrc·2022-04-12·CVSS 7.5
CVE-2022-26830 [HIGH] DiskUsage.exe Remote Code Execution Vulnerability
DiskUsage.exe Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
This vulnerability requires that a user with an affected version of Windows access a malicious server. An attacker would have to host a specially crafted server share or website. An attacker would have no way to force users to visit this specially crafted server share or website, but would have to convince them to visit the server share or website, typically by
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-15
Published