Lucene search

K
mscveMicrosoftMS:CVE-2022-21907
HistoryJan 11, 2022 - 8:00 a.m.

HTTP Protocol Stack Remote Code Execution Vulnerability

2022-01-1108:00:00
Microsoft
msrc.microsoft.com
82
http protocol stack
remote code execution
vulnerability
microsoft

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.876

Percentile

98.7%

Affected configurations

Vulners
Node
microsoftwindows_server_2019Range<10.0.17763.2452
OR
microsoftwindows_server_2019Range<10.0.17763.2452
OR
microsoftwindows_10_21h2Range<10.0.19044.1466
OR
microsoftwindows_10_21h2Range<10.0.19044.1466
OR
microsoftwindows_11_21h2Range<10.0.22000.434
OR
microsoftwindows_11_21h2Range<10.0.22000.434
OR
microsoftwindows_server_20h2Range<10.0.19042.1466
OR
microsoftwindows_10_20h2Range<10.0.19042.1466
OR
microsoftwindows_10_20h2Range<10.0.19042.1466
OR
microsoftwindows_server_2022Range<10.0.20348.469
OR
microsoftwindows_server_2022Range<10.0.20348.469
OR
microsoftwindows_10_21h1Range<10.0.19043.1466
OR
microsoftwindows_10_21h1Range<10.0.19043.1466
OR
microsoftwindows_10_21h1Range<10.0.19043.1466
OR
microsoftwindows_10_21h2Range<10.0.19044.1466
OR
microsoftwindows_10_1809Range<10.0.17763.2452
OR
microsoftwindows_10_1809Range<10.0.17763.2452
OR
microsoftwindows_10_1809Range<10.0.17763.2452
VendorProductVersionCPE
microsoftwindows_server_2019*cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
microsoftwindows_10_21h2*cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*
microsoftwindows_11_21h2*cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*
microsoftwindows_server_20h2*cpe:2.3:o:microsoft:windows_server_20h2:*:*:*:*:*:*:*:*
microsoftwindows_10_20h2*cpe:2.3:o:microsoft:windows_10_20h2:*:*:*:*:*:*:*:*
microsoftwindows_server_2022*cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
microsoftwindows_10_21h1*cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:*:*
microsoftwindows_10_1809*cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.876

Percentile

98.7%