CVE-2022-41118
published 2022-11-09CVE-2022-41118: Windows Scripting Languages Remote Code Execution Vulnerability
PriorityP342high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
1.06%
60.9th percentile
Windows Scripting Languages Remote Code Execution Vulnerability
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19567 | 10.0.10240.19567 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2251 | 10.0.19042.2251 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.2251 | 10.0.19043.2251 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2251 | 10.0.19044.2251 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2251 | 10.0.19045.2251 |
| microsoft | windows_11 | — | — |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1219 | 10.0.22000.1219 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.819 | 10.0.22621.819 |
| microsoft | windows_7 | — | — |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.26221 | 6.1.7601.26221 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.26221 | 6.1.7601.26221 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20671 | 6.3.9600.20671 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26221 | 6.1.7601.26221 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20671 | 6.3.9600.20671 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-84wj-46vv-37cw: Windows Scripting Languages Remote Code Execution Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 8.8
CVE-2022-41118 [HIGH] CWE-362 GHSA-84wj-46vv-37cw: Windows Scripting Languages Remote Code Execution Vulnerability
Windows Scripting Languages Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-41128.
GHSA
GHSA-778m-x5h7-mg59: Windows Scripting Languages Remote Code Execution Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 7.5
CVE-2022-41128 [HIGH] CWE-787 GHSA-778m-x5h7-mg59: Windows Scripting Languages Remote Code Execution Vulnerability
Windows Scripting Languages Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-41118.
Microsoft
Windows Scripting Languages Remote Code Execution Vulnerability
vendor_msrc·2022-11-08·CVSS 7.5
CVE-2022-41118 [HIGH] Windows Scripting Languages Remote Code Execution Vulnerability
Windows Scripting Languages Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: The CVE title says Windows Scripting Languages, what does that mean for this vulnerability?
This vulnerability impacts both the JScript9 and Chakra scripting languages.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
This vulnerability requires that a user with an affected version of Windows access a malicious server. An attacker would have to host a specially crafted server share or website. An attacker would have no way to force users to visit t
No detection rules found.
No public exploits indexed.
Qualys
November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years).
blogs_qualys·2022-11-08·CVSS 7.5
[HIGH] November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years).
## Table of Contents
Microsoft Patch Tuesday Summary
The November 2022 Microsoft Vulnerabilities are Classified as Follows:
OpenSSL 3.x Critical Vulnerability Highlights
OpenSSL 3.x Related Blogs and Resources
Microsoft Addressed Six Zero-Day Vulnerabilities
Microsoft Patch Tuesday Critical Vulnerability Highlights
Microsoft Release Summary
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Qualys Threat Research Blog Posts
Qualys Threat Protection High-Rated Advisories
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
Rapid Response with Patch Management (PM)
Extend the Power of VMDR to Enterprise Mobile Devices With Qualys VMDR Mobile
Execute Mitigation UsingCustom Assessment and Remediation(CAR)
Patch Tuesday Is
Talos
Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-11-08·CVSS 8.1
CVE-2022-41039 [HIGH] Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 62 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical” and the rest are classified as “Important.”
Three of the critical entries are remote code execution (RCE) vulnerabilities for Windows Point-to-Point Tunneling Protocol (PPTP).
CVE-2022-41039
CVE-2022-41044
CVE-2022-41088
An unauthenticated attacker can send a specially crafted request to an RAS (Remote Access Server), which may lead to remote code execution. Although according to Microsoft, these three vulnerabilities are less likely to be exploited, as the attacker must win a complex race condition. In August of 2022’s Patch Tuesday release, several v
Tenable
Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
blogs_tenable·2022-11-08·CVSS 7.8
[HIGH] Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years). | Qualys
blogs_qualys·2022-11-08·CVSS 7.5
[HIGH] November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years). | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The November 2022 Microsoft Vulnerabilities are Classified as Follows:
- OpenSSL 3.x Critical Vulnerability Highlights
- OpenSSL 3.x Related Blogs and Resources
- Microsoft Addressed Six Zero-Day Vulnerabilities
- Microsoft Patch Tuesday Critical Vulnerability Highlights
- Microsoft Release Summary
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Qualys Threat Research Blog Posts
- Qualys Threat Protection High-Rated Advisories
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
- Rapid Response with Patch Management (PM)
- Extend the Power of VMDR to Enterprise Mobile Devices With Qualys VMDR Mobile
- Execute Mitigation UsingCustom Assessment and Remediation(CAR)
Talos
Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-11-08·CVSS 8.1
CVE-2022-41039 [HIGH] Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 62 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical” and the rest are classified as “Important.”
Three of the critical entries are remote code execution (RCE) vulnerabilities for Windows Point-to-Point Tunneling Protocol (PPTP).
- CVE-2022-41039
- CVE-2022-41044
- CVE-2022-41088
An unauthenticated attacker can send a specially crafted request to an RAS (Remote Access Server), which may lead to remote code execution. Although according to Microsoft, these three vulnerabilities are less likely to be exploited, as the attacker must win a complex race condition. In August of 2022’s Patch Tuesday release, several vulnerabilities for Windows PPTP were also disclosed.
Another notable vulnerability in
2022-11-09
Published