CVE-2022-35743
published 2023-05-31CVE-2022-35743: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.45%
70.5th percentile
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19387 | 10.0.10240.19387 |
| microsoft | windows_10_1607 | < 10.0.14393.5291 | 10.0.14393.5291 |
| microsoft | windows_10_1809 | < 10.0.17763.3287 | 10.0.17763.3287 |
| microsoft | windows_10_20h2 | < 10.0.19042.1889 | 10.0.19042.1889 |
| microsoft | windows_10_21h1 | < 10.0.19043.1889 | 10.0.19043.1889 |
| microsoft | windows_10_21h2 | < 10.0.19044.1889 | 10.0.19044.1889 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19387 | 10.0.10240.19387 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5291 | 10.0.14393.5291 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3287 | 10.0.17763.3287 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3287 | 10.0.17763.3287 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1889 | 10.0.19042.1889 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1889 | 10.0.19043.1889 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1889 | 10.0.19044.1889 |
| microsoft | windows_11_21h2 | < 10.0.22000.856 | 10.0.22000.856 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.856 | 10.0.22000.856 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.26065 | 6.1.7601.26065 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.26065 | 6.1.7601.26065 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20520 | 6.3.9600.20520 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26065 | 6.1.7601.26065 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23817 | 6.2.9200.23817 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20520 | 6.3.9600.20520 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5291 | 10.0.14393.5291 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.3287 | 10.0.17763.3287 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6xp4-7cvm-mcjw: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
ghsa_unreviewed·2023-05-31
CVE-2022-35743 [HIGH] CWE-94 GHSA-6xp4-7cvm-mcjw: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
GHSA
GHSA-86f2-7h4r-pc7m: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
ghsa_unreviewed·2022-08-10·CVSS 7.8
CVE-2022-34713 [HIGH] GHSA-86f2-7h4r-pc7m: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-35743.
Microsoft
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
vendor_msrc·2022-08-09·CVSS 7.8
CVE-2022-35743 [HIGH] Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally.
For example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on their computer.
Microsoft Windows Support Diagnostic Tool (MSDT): Microsoft Windows
No detection rules found.
No public exploits indexed.
Securelist
IT threat evolution in Q3 2022. Non-mobile statistics
blogs_securelist·2022-11-18
IT threat evolution in Q3 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Number of users attacked by banking malware
TOP 10 banking malware families
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
TOP 20 threats for macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
Countries and territories that serve as sources of web-ba
Securelist
PC malware statistics, Q3 2022
blogs_securelist·2022-11-18
PC malware statistics, Q3 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q3 2022
- IT threat evolution in Q3 2022. Non-mobile statistics
- IT threat evolution in Q3 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3 2022:
- Kaspersky solutions blocked 956,074,958 attacks from online resources across the globe.
- Web Anti-Virus recognized 251,288,987 unique URLs as malicious.
- Attempts to run malware fo
Talos
Threat Source newsletter (Aug. 11, 2022) — All of the things-as-a-service
blogs_talos·2022-08-11
Threat Source newsletter (Aug. 11, 2022) — All of the things-as-a-service
Welcome to this week’s edition of the Threat Source newsletter.
Everyone seems to want to create the next “Netflix” of something. Xbox’s Game Pass is the “Netflix of video games.” Rent the Runway is a “Netflix of fashion” where customers subscribe to a rotation of fancy clothes.
And now threat actors are looking to be the “Netflix of malware.” All categories of malware have some sort of "as-a-service" twist now. Some of the largest ransomware groups in the world operate “as a service,” allowing smaller groups to pay a fee in exchange for using the larger group’s tools.
Our latest report on information-stealers points out that “infostealers as-a-service" are growing in popularity, and our researchers also discovered a new “C2 as-a-service" platform where attackers can pay to have this th
Talos
Threat Source newsletter (Aug. 11, 2022) — All of the things-as-a-service
blogs_talos·2022-08-11
Threat Source newsletter (Aug. 11, 2022) — All of the things-as-a-service
## Threat Source newsletter (Aug. 11, 2022) — All of the things-as-a-service
Welcome to this week’s edition of the Threat Source newsletter.
Everyone seems to want to create the next “Netflix” of something. Xbox’s Game Pass is the “Netflix of video games.” Rent the Runway is a “Netflix of fashion” where customers subscribe to a rotation of fancy clothes.
And now threat actors are looking to be the “Netflix of malware.” All categories of malware have some sort of " as-a-service " twist now. Some of the largest ransomware groups in the world operate “as a service,” allowing smaller groups to pay a fee in exchange for using the larger group’s tools.
Our latest report on information-stealers points out that “infostealers as-a-service" are growing in popularity, and our researchers also dis
Krebs
Microsoft Patch Tuesday, August 2022 Edition
blogs_krebs·2022-08-10·CVSS 8.0
[HIGH] Microsoft Patch Tuesday, August 2022 Edition
Microsoft today released updates to fix a record 141 security vulnerabilities in its Windows operating systems and related software. Once again, Microsoft is patching a zero-day vulnerability in the Microsoft Support Diagnostics Tool (MSDT), a service built into Windows. Redmond also addressed multiple flaws in Exchange Server — including one that was disclosed publicly prior to today — and it is urging organizations that use Exchange for email to update as soon as possible and to enable additional protections.
In June, Microsoft patched a vulnerability in MSDT dubbed “Follina” that had been used in active attacks for at least three months prior. This latest MSDT bug — CVE-2022-34713 — is a remote code execution flaw that requires convincing a target to open a booby-trapped file, such as
Tenable
Microsoft’s August 2022 Patch Tuesday Addresses 118 CVEs (CVE-2022-34713)
blogs_tenable·2022-08-09·CVSS 7.8
[HIGH] Microsoft’s August 2022 Patch Tuesday Addresses 118 CVEs (CVE-2022-34713)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday for August 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-08-09·CVSS 8.0
[HIGH] Microsoft Patch Tuesday for August 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing more than 120 vulnerabilities across its line of products and software, the most in a single Patch Tuesday in four months.
This batch of updates also includes a fix for a new vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT) that’s actively being exploited in the wild, according to Microsoft. MSDT was already the target of the so-called “Follina” zero-day vulnerability in June.
In all, August’s Patch Tuesday includes 15 critical vulnerabilities and a single low- and moderate-severity issue. The remainder is classified as “important.”
Two of the important vulnerabilities CVE-2022-35743 and CVE-2022-34713 are remote code execution vulnerabilities in MSDT. However, only CVE-2022-34713 has been exploited
Talos
Microsoft Patch Tuesday for August 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-08-09·CVSS 8.0
[HIGH] Microsoft Patch Tuesday for August 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for August 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing more than 120 vulnerabilities across its line of products and software, the most in a single Patch Tuesday in four months .
This batch of updates also includes a fix for a new vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT) that’s actively being exploited in the wild, according to Microsoft. MSDT was already the target of the so-called “Follina” zero-day vulnerability in June.
In all, August’s Patch Tuesday includes 15 critical vulnerabilities and a single low- and moderate-severity issue. The remainder is classified as “important.”
Two of the important vulnerabilities CVE-2022-35743 and CVE-2022-34713 are remote
Krebs
Microsoft Patch Tuesday, August 2022 Edition
blogs_krebs·2022-08-09·CVSS 8.0
[HIGH] Microsoft Patch Tuesday, August 2022 Edition
Microsoft today released updates to fix a record 141 security vulnerabilities in its Windows operating systems and related software. Once again, Microsoft is patching a zero-day vulnerability in the Microsoft Support Diagnostics Tool (MSDT), a service built into Windows. Redmond also addressed multiple flaws in Exchange Server — including one that was disclosed publicly prior to today — and it is urging organizations that use Exchange for email to update as soon as possible and to enable additional protections.
In June, Microsoft patched a vulnerability in MSDT dubbed “ Follina ” that had been used in active attacks for at least three months prior . This latest MSDT bug — CVE-2022-34713 — is a remote code execution flaw that requires convincing a target to open a booby-trapped file, such
2023-05-31
Published