⚠ Actively exploited
Added to CISA KEV on 2022-08-09. Federal agencies required to patch by 2022-08-30. Required action: Apply updates per vendor instructions..

CVE-2022-34713Microsoft Windows 10 Version 1507 vulnerability

15 documents10 sources
Severity
7.8HIGHNVD
EPSS
3.3%
top 12.85%
CISA KEV
KEV
Added 2022-08-09
Due 2022-08-30
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedAug 9
KEV addedAug 9
Latest updateAug 10
KEV dueAug 30
CISA Required Action: Apply updates per vendor instructions.

Description

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages25 packages

NVDmicrosoft/windows< 10.0.14393.5291+4
CVEListV5microsoft/windows_76.1.06.1.7601.26065
CVEListV5microsoft/windows_8.16.3.06.3.9600.20520
NVDmicrosoft/windows_10_1507< 10.0.10240.19387
NVDmicrosoft/windows_10_1607< 10.0.14393.5291

Patches

🔴Vulnerability Details

3
GHSA
GHSA-86f2-7h4r-pc7m: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability2022-08-10
CVEList
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability2022-08-09
VulnCheck
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability2022

📋Vendor Advisories

2
CISA
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability2022-08-09
Microsoft
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability2022-08-09

🕵️Threat Intelligence

5
Krebs
Microsoft Patch Tuesday, August 2022 Edition2022-08-10
Trendmicro
Microsoft Patches Zero-Day DogWalk Vulnerability
Trendmicro
Microsoft Patches Zero-Day DogWalk Vulnerability
Trendmicro
Microsoft Patches Zero-Day DogWalk Vulnerability
Trendmicro
Microsoft Patches Zero-Day DogWalk Vulnerability