CVE-2022-22017
CVSS 2.0 Score 9.3 of 10 (high)
Details
Published May 10, 2022
Updated: Jan 2, 2025
Summary
CVE-2022-22017 is a newly discovered remote code execution vulnerability affecting Remote Desktop Clients. An attacker can exploit this weakness by sending specially crafted RDP packets to a target system, potentially gaining unauthorized access and executing malicious code. Successful exploitation could lead to significant security compromises, including data theft or system takeover. Users are advised to apply relevant patches or updates as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Windows Server 2022
- Microsoft Windows 11
- Microsoft Remote Desktop
Affected Vendors
- Microsoft