CVE-2022-37958
published 2022-09-13CVE-2022-37958: SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
PriorityP267high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
85.76%
99.7th percentile
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19444 | 10.0.10240.19444 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5356 | 10.0.14393.5356 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3406 | 10.0.17763.3406 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3406 | 10.0.17763.3406 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2006 | 10.0.19042.2006 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.2006 | 10.0.19043.2006 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2006 | 10.0.19044.2006 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.978 | 10.0.22000.978 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.26115 | 6.1.7601.26115 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.26115 | 6.1.7601.26115 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20571 | 6.3.9600.20571 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26115 | 6.1.7601.26115 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23865 | 6.2.9200.23865 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20571 | 6.3.9600.20571 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5356 | 10.0.14393.5356 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.3406 | 10.0.17763.3406 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.1006 | 10.0.20348.1006 |
| msrc | windows_10 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-37958 affects SPNEGO NEGOEX across multiple protocols including SMB, RDP, HTTP, and SMTP — monitor authentication negotiation traffic on all these protocol ports, not just SMB, for anomalous NEGOEX exchanges ↗
- →Both SMB and RDP use NEGOEX by default; SMTP and HTTP can be configured to use it — inspect NEGOEX tokens in GSSAPI/SPNEGO authentication blobs on these protocols for malformed or unexpected negotiation messages ↗
- →Successful exploitation requires attacker preparation of the target environment; look for reconnaissance or staging activity preceding NEGOEX-based authentication attempts ↗
- →Use Qualys VMDR QIDs 91940 and 91945 to detect systems vulnerable to CVE-2022-37958 ↗
- ·No public PoC exploit code existed at time of publication; IBM X-Force Red planned to release full technical details including a possible PoC in Q2 2023 ↗
- ·No confirmed in-the-wild exploitation had been observed at time of publication ↗
- ·Organizations that applied September 2022 Patch Tuesday updates are already protected; the December 2022 reclassification was informational only and did not introduce new patches ↗
- ·Security updates for Microsoft Office 2019 for Mac and Microsoft Office LTSC for Mac 2021 were not immediately available at time of the advisory ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_msrc8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux-iot vulnerabilities
osv·2026-01-12·CVSS 7.8
CVE-2022-49026 linux-iot vulnerabilities
linux-iot vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Cryptographic API;
- ACPI drivers;
- InfiniBand drivers;
- Media drivers;
- Network drivers;
- Pin controllers subsystem;
- AFS file system;
- F2FS file system;
- Tracing infrastructure;
- Memory management;
- Appletalk network protocol;
- Netfilter;
(CVE-2022-49026, CVE-2022-49390, CVE-2024-47691, CVE-2024-49935,
CVE-2024-50067, CVE-2024-50095, CVE-2024-50196, CVE-2024-53090,
CVE-2024-53218, CVE-2025-21855, CVE-2025-37958, CVE-2025-38666,
CVE-2025-39964, CVE-2025-39993, CVE-2025-40018)
OSV
linux-raspi, linux-raspi-5.4 vulnerabilities
osv·2026-01-06·CVSS 7.8
linux-raspi, linux-raspi-5.4 vulnerabilities
linux-raspi, linux-raspi-5.4 vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Cryptographic API;
- ACPI drivers;
- InfiniBand drivers;
- Media drivers;
- Network drivers;
- Pin controllers subsystem;
- AFS file system;
- F2FS file system;
- Tracing infrastructure;
- Memory management;
- Appletalk network protocol;
- Netfilter;
(CVE-2022-49026, CVE-2022-49390, CVE-2024-47691, CVE-2024-49935,
CVE-2024-50067, CVE-2024-50095, CVE-2024-50196, CVE-2024-53090,
CVE-2024-53218, CVE-2025-21855, CVE-2025-37958, CVE-2025-38666,
CVE-2025-39964, CVE-2025-39993, CVE-2025-40018)
OSV
linux-oracle-5.4 vulnerabilities
osv·2025-12-19·CVSS 7.8
linux-oracle-5.4 vulnerabilities
linux-oracle-5.4 vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Cryptographic API;
- ACPI drivers;
- InfiniBand drivers;
- Media drivers;
- Network drivers;
- Pin controllers subsystem;
- AFS file system;
- F2FS file system;
- Tracing infrastructure;
- Memory management;
- Appletalk network protocol;
- Netfilter;
(CVE-2022-49026, CVE-2022-49390, CVE-2024-47691, CVE-2024-49935,
CVE-2024-50067, CVE-2024-50095, CVE-2024-50196, CVE-2024-53090,
CVE-2024-53218, CVE-2025-21855, CVE-2025-37958, CVE-2025-38666,
CVE-2025-39964, CVE-2025-39993, CVE-2025-40018)
OSV
linux-fips, linux-aws-fips, linux-gcp-fips vulnerabilities
osv·2025-12-11·CVSS 7.8
linux-fips, linux-aws-fips, linux-gcp-fips vulnerabilities
linux-fips, linux-aws-fips, linux-gcp-fips vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Cryptographic API;
- ACPI drivers;
- InfiniBand drivers;
- Media drivers;
- Network drivers;
- Pin controllers subsystem;
- AFS file system;
- F2FS file system;
- Tracing infrastructure;
- Memory management;
- Appletalk network protocol;
- Netfilter;
(CVE-2022-49026, CVE-2022-49390, CVE-2024-47691, CVE-2024-49935,
CVE-2024-50067, CVE-2024-50095, CVE-2024-50196, CVE-2024-53090,
CVE-2024-53218, CVE-2025-21855, CVE-2025-37958, CVE-2025-38666,
CVE-2025-39964, CVE-2025-39993, CVE-2025-40018)
GHSA
GHSA-w9jc-m3x9-g758: SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Information Disclosure Vulnerability
ghsa_unreviewed·2022-09-14
CVE-2022-37958 [HIGH] CWE-668 GHSA-w9jc-m3x9-g758: SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Information Disclosure Vulnerability
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Information Disclosure Vulnerability.
Microsoft
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
vendor_msrc·2022-09-13·CVSS 8.1
CVE-2022-37958 [HIGH] SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
FAQ: What is SPNEGO Extended Negotiation?
The SPNEGO Extended Negotiation Security Mechanism (NEGOEX) extends Simple and Protected GSS-API Negotiation Mechanism (SPNEGO) described in [RFC4178]. Please see SPNEGO Overview for more information.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to prepare the target environment to improve exploit reliability.
FAQ: Are the updates for the Microsoft Office for Mac currently available?
The security update for Microsoft Office 2019 for Mac and Microsoft Office LTSC for Mac 2021 are not immediately available. The updates w
No detection rules found.
No public exploits indexed.
Qualys
Qualys Threat Research Unit: Threat Thursdays, December 2022
blogs_qualys·2022-12-29
Qualys Threat Research Unit: Threat Thursdays, December 2022
## Table of Contents
From the Qualys Blogs
New Tools & Techniques
New Vulnerabilities
Threat Thursdays Webinar
Welcome to the fourth edition of the Qualys Threat Research Unit’s (TRU) “Threat Research Thursday”, where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. This also happens to be the last edition for the year. Feedback on our third edition, Qualys Threat Research Thursday , is more than welcome. We would love to hear from you!
## From the Qualys Blogs
Here is a roundup of the most interesting blogs from the Qualys Research Team over the past couple of weeks:
Dissecting the Empire C2 Framework – In this blog post, we take a quick dive into Empire, a popular open-source post-exploitation fra
Qualys
Qualys Threat Research Unit: Threat Thursdays, December 2022 | Qualys
blogs_qualys·2022-12-29
Qualys Threat Research Unit: Threat Thursdays, December 2022 | Qualys
#### Table of Contents
- From the Qualys Blogs
- New Tools & Techniques
- New Vulnerabilities
- Threat Thursdays Webinar
Welcome to the fourth edition of the Qualys Threat Research Unit’s (TRU) “Threat Research Thursday”, where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. This also happens to be the last edition for the year. Feedback on our third edition, Qualys Threat Research Thursday, is more than welcome. We would love to hear from you!
## From the Qualys Blogs
Here is a roundup of the most interesting blogs from the Qualys Research Team over the past couple of weeks:
- Dissecting the Empire C2 Framework – In this blog post, we take a quick dive into Empire, a popular open-source post-exploita
Tenable
CVE-2022-37958: FAQ for Critical Microsoft SPNEGO NEGOEX Vulnerability
blogs_tenable·2022-12-21·CVSS 8.1
[HIGH] CVE-2022-37958: FAQ for Critical Microsoft SPNEGO NEGOEX Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Schneier
Critical Microsoft Code-Execution Vulnerability - Schneier on Security
blogs_schneier·2022-12-01·CVSS 8.1
CVE-2022-37958 [HIGH] Critical Microsoft Code-Execution Vulnerability - Schneier on Security
## Critical Microsoft Code-Execution Vulnerability
A critical code-execution vulnerability in Microsoft Windows was patched in September. It seems that researchers just realized how serious it was (and is):
Like EternalBlue, CVE-2022-37958, as the latest vulnerability is tracked, allows attackers to execute malicious code with no authentication required. Also, like EternalBlue, it’s wormable, meaning that a single exploit can trigger a chain reaction of self-replicating follow-on exploits on other vulnerable systems. The wormability of EternalBlue allowed WannaCry and several other attacks to spread across the world in a matter of minutes with no user interaction required.
But unlike EternalBlue, which could be exploited when using only the SMB, or server message block, a protocol for f
2022-09-13
Published