cbcvebase.
CVE-2022-29137
published 2022-05-10

CVE-2022-29137: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.27%
81.1th percentile
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.1929710.0.10240.19297
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.512510.0.14393.5125
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.292810.0.17763.2928
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.292810.0.17763.2928
microsoftwindows_10_version_1909>= 10.0.0 < 10.0.18363.227410.0.18363.2274
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.170610.0.19042.1706
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.170610.0.19043.1706
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19043.170610.0.19043.1706
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.67510.0.22000.675
microsoftwindows_7>= 6.1.0 < 6.1.7601.259546.1.7601.25954
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.259546.1.7601.25954
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.203716.3.9600.20371
microsoftwindows_server
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.259546.1.7601.25954
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.214816.0.6003.21481
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.237146.2.9200.23714
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.203716.3.9600.20371

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2022-29137 affects Windows LDAP (Lightweight Directory Access Protocol) and is a Remote Code Execution vulnerability; monitor for anomalous or malformed LDAP traffic targeting Windows domain controllers and LDAP servers
  • Exploitation has not been publicly observed but is rated 'Exploitation Less Likely' for both latest and older software releases; prioritize patching on exposed LDAP services (default TCP/UDP 389, 636)
  • ·Customer action is required — apply the relevant Microsoft security updates (KB5013941, KB5013945, KB5013942, KB5013944, KB5013943, KB5013963, KB5013952, KB5014012, KB5013999, KB5014011, KB5014001, KB5014025, KB5014010, KB5014006, KB5014017, KB5014018) to remediate this vulnerability across affected Windows versions

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.