CVE-2022-38011
published 2022-09-13CVE-2022-38011: Raw Image Extension Remote Code Execution Vulnerability
PriorityP337high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.80%
52.5th percentile
Raw Image Extension Remote Code Execution Vulnerability
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | raw_image_extension | >= 2.1.0.0 < v2.0.32061.0 | v2.0.32061.0 |
| msrc | raw_image_extension_on_windows_10_for_32-bit_systems | — | — |
| msrc | raw_image_extension_on_windows_10_for_x64-based_systems | — | — |
| msrc | raw_image_extension_on_windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | raw_image_extension_on_windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | raw_image_extension_on_windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | raw_image_extension_on_windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | raw_image_extension_on_windows_10_version_1809_for_hololens | — | — |
| msrc | raw_image_extension_on_windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | raw_image_extension_on_windows_10_version_20h2_for_32-bit_systems | — | — |
| msrc | raw_image_extension_on_windows_10_version_20h2_for_arm64-based_systems | — | — |
| msrc | raw_image_extension_on_windows_10_version_21h1_for_32-bit_systems | — | — |
| msrc | raw_image_extension_on_windows_10_version_21h1_for_arm64-based_systems | — | — |
| msrc | raw_image_extension_on_windows_10_version_21h1_for_x64-based_systems | — | — |
| msrc | raw_image_extension_on_windows_10_version_21h2_for_32-bit_systems | — | — |
| msrc | raw_image_extension_on_windows_10_version_21h2_for_arm64-based_systems | — | — |
| msrc | raw_image_extension_on_windows_10_version_21h2_for_x64-based_systems | — | — |
| msrc | raw_image_extension_on_windows_11_version_21h2_for_arm64-based_systems | — | — |
| msrc | raw_image_extension_on_windows_11_version_21h2_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Raw Image Extension Remote Code Execution Vulnerability
vendor_msrc·2022-09-13·CVSS 7.3
CVE-2022-38011 [HIGH] Raw Image Extension Remote Code Execution Vulnerability
Raw Image Extension Remote Code Execution Vulnerability
FAQ: How do I get the updated app?
The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details.
My system is in a disconnected environment; is it vulnerable?
It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers. VLSC customers can visit the Volume Licensing Servicing Center to get the update https://www.microsoft.com/Licensing/servicecenter/.
Customers using the Microsoft Store for Business and Microsoft Store for Education can get this update through their organizations.
FAQ: According to the CVSS metric, the attack vector is local (AV:L)
GHSA
GHSA-gw9q-37r7-h423: Raw Image Extension Remote Code Execution Vulnerability
ghsa_unreviewed·2022-09-14
CVE-2022-38011 [HIGH] GHSA-gw9q-37r7-h423: Raw Image Extension Remote Code Execution Vulnerability
Raw Image Extension Remote Code Execution Vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-13
Published