CVE-2022-30216
published 2022-07-12CVE-2022-30216: Windows Server Service Tampering Vulnerability Windows Server Service Tampering Vulnerability
high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
88.61%
99.8th percentile
Windows Server Service Tampering Vulnerability
Windows Server Service Tampering Vulnerability
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | — | — |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1826 | 10.0.19042.1826 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1826 | 10.0.19043.1826 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1826 | 10.0.19044.1826 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.795 | 10.0.22000.795 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.825 | 10.0.20348.825 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1826 | 10.0.19042.1826 |
| msrc | windows_10_version_20h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_20h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h1_for_32-bit_systems | — | — |
| msrc | windows_10_version_21h1_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h1_for_x64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_21h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_21h2_for_arm64-based_systems | — | — |
| msrc | windows_11_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_version_20h2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploitation requires an authenticated attacker to remotely upload a malicious certificate to the Windows Server Service; monitor for unexpected certificate uploads or imports on Server service endpoints. ↗
- →A malicious certificate must be imported on the affected system as part of the attack chain; alert on anomalous certificate import events (e.g., CertUtil usage or certificate store modifications) from non-administrative or remote sources. ↗
- ·Microsoft rates exploitation as 'More Likely' for both latest and older software releases, indicating active risk despite no confirmed in-the-wild exploitation at time of disclosure. ↗
- ·The vulnerability is classified as a Tampering impact against the Windows Server Service, not a direct code execution primitive — detection and response should account for post-exploitation tampering scenarios. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
cvelistv58.8HIGH
vendor_apache8.8HIGH
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Server Service Tampering Vulnerability
vendor_msrc·2022-07-12·CVSS 8.8
CVE-2022-30216 [HIGH] Windows Server Service Tampering Vulnerability
Windows Server Service Tampering Vulnerability
FAQ: How could an attacker exploit this vulnerability?
For successful exploitation, a malicious certificate needs to be imported on an affected system. An authenticated attacker could remotely upload a certificate to the Server service.
Windows Server Service: Windows Server Service
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Tampering
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5015807
Reference: https://support.microsoft.com/help/5015807
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5015827
Reference: https://s
Apache
Apache tika: CVE-2022-30216
vendor_apache·CVSS 8.8
CVE-2022-30216 [HIGH] Apache tika: CVE-2022-30216
Apache tika: CVE-2022-30216
and a new one Tony Torralba, Jaroslav Lobačevski and Tim Allison ???-2.4.0 and ???-1.28.3
CVEList
Windows Server Service Tampering Vulnerability
cvelistv5·2022-07-12·CVSS 8.8
CVE-2022-30216 [HIGH] Windows Server Service Tampering Vulnerability
Windows Server Service Tampering Vulnerability
Windows Server Service Tampering Vulnerability
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-07-12·CVSS 8.1
[HIGH] Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing more than 80 vulnerabilities in the company’s various software, hardware and firmware offerings, including one that’s actively being exploited in the wild.
July's security update features three critical vulnerabilities, up from one last month, still lower than Microsoft’s average in a Patch Tuesday. All the other vulnerabilities fixed are considered “important.”
All three critical vulnerabilities allow remote code execution on Microsoft Windows Systems. Of these, Microsoft considers the exploitation of CVE-2022-22029 , CVE-2022-22038 and CVE-2022-22039 less likely to occur. CVE-2022-22029 could be exploited over the network by making an
Talos
Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-07-12·CVSS 8.1
[HIGH] Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing more than 80 vulnerabilities in the company’s various software, hardware and firmware offerings, including one that’s actively being exploited in the wild.
July's security update features three critical vulnerabilities, up from one last month, still lower than Microsoft’s average in a Patch Tuesday. All the other vulnerabilities fixed are considered “important.”
All three critical vulnerabilities allow remote code execution on Microsoft Windows Systems. Of these, Microsoft considers the exploitation of CVE-2022-22029, CVE-2022-22038 and CVE-2022-22039 less likely to occur. CVE-2022-22029 could be exploited over the network by making an unauthenticated, specially crafted call to a Network File System (NFS). However, accord
2022-07-12
Published