⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2022-34721Microsoft Windows 10 Version 1507 vulnerability

5 documents5 sources
Severity
9.8CRITICALNVD
EPSS
26.6%
top 3.66%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedSep 13
Latest updateSep 14

Description

Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages19 packages

CVEListV5microsoft/windows_76.1.06.1.7601.26115
CVEListV5microsoft/windows_8.16.3.06.3.9600.20571
CVEListV5microsoft/windows_server_20126.2.9200.06.2.9200.23865
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.5356
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.3406

🔴Vulnerability Details

3
GHSA
GHSA-hppf-3fwv-wwmm: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability2022-09-14
CVEList
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability2022-09-13
VulnCheck
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution2022

📋Vendor Advisories

1
Microsoft
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability2022-09-13
CVE-2022-34721 — Microsoft vulnerability | cvebase