CVE-2022-22015
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2022-22015 is a newly disclosed vulnerability affecting Microsoft Remote Desktop Protocol (RDP). This issue permits an attacker to gain unintended access to information, specifically the Windows Event Log, by exploiting a flaw in RDP's handling of certain requests. Successful exploitation may lead to the exposure of sensitive system details, potentially allowing further attacks. Microsoft has issued a security update to address this vulnerability, and it is strongly recommended that users apply the patch as soon as possible to protect their systems from potential information disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 7
- Microsoft Windows 10
- Microsoft Windows 8.1
- Microsoft Windows Server 2012
- Microsoft Windows Server 2016
Affected Vendors
- Microsoft