CVE-2022-26913
published 2022-05-10CVE-2022-26913: Windows Authentication Information Disclosure Vulnerability
PriorityP341high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
2.31%
81.4th percentile
Windows Authentication Information Disclosure Vulnerability
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2928 | 10.0.17763.2928 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2928 | 10.0.17763.2928 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2274 | 10.0.18363.2274 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1706 | 10.0.19042.1706 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1706 | 10.0.19043.1706 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19043.1706 | 10.0.19043.1706 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.675 | 10.0.22000.675 |
| microsoft | windows_server | — | — |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.2928 | 10.0.17763.2928 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.707 | 10.0.20348.707 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1706 | 10.0.19042.1706 |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_version_20h2 | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_msrc7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-58h8-g2p9-78p3: Windows Authentication Security Feature Bypass Vulnerability
ghsa_unreviewed·2022-05-11
CVE-2022-26913 [HIGH] CWE-863 GHSA-58h8-g2p9-78p3: Windows Authentication Security Feature Bypass Vulnerability
Windows Authentication Security Feature Bypass Vulnerability.
Microsoft
Windows Authentication Information Disclosure Vulnerability
vendor_msrc·2022-05-10·CVSS 7.4
CVE-2022-26913 [HIGH] Windows Authentication Information Disclosure Vulnerability
Windows Authentication Information Disclosure Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
The attacker must inject themselves into the logical network path between the target and the resource requested by the victim to read or modify network communications. This is called a machine-in-the-middle (MITM) attack.
FAQ: How could an attacker exploit this vulnerability?
An attacker who successfully exploited this vulnerability could carry out a machine-in-the-middle (MITM) attack and could decrypt and read or modify TLS traffic between the client and server. There is no impact to the availability of the attacked machine (A:N).
Windows Authentication Methods: Windows Authentication Methods
Microsoft: Micros
No detection rules found.
No public exploits indexed.
Qualys
May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical.
blogs_qualys·2022-05-10·CVSS 5.6
[MEDIUM] May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
Notable Microsoft Vulnerabilities Patched
Microsoft Last But Not Least
Notable Adobe Vulnerabilities Patched
About Qualys Patch Tuesday
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response with Patch Management (PM)
Qualys Monthly Webinar Series
Join the webinar this Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 75 vulnerabilities in the May 2022 update, including one advisory ( ADV220001 ) for Azure in response to CVE-2022-29972 , a publicly exposed Zero-Day Remote Code Execution (RCE) Vulnerability, and eight vulnerabilities classified as critical as they allow Remote Code Execution (RCE) or Elevation of Privileges. This month
Qualys
May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical. | Qualys
blogs_qualys·2022-05-10·CVSS 5.6
[MEDIUM] May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- Notable Microsoft Vulnerabilities Patched
- Microsoft Last But Not Least
- Notable Adobe Vulnerabilities Patched
- About Qualys Patch Tuesday
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response with Patch Management (PM)
- Qualys Monthly Webinar Series
- Join the webinar this Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 75 vulnerabilities in the May 2022 update, including one advisory ( ADV220001 ) for Azure in response to CVE-2022-29972, a publicly exposed Zero-Day Remote Code Execution (RCE) Vulnerability, and eight vulnerabilities classified as critical as they allow Remote Code Execution (RCE) or Elevation of Privileges.
2022-05-10
Published