CVE-2022-38047

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Oct 11, 2022
Updated: Jan 2, 2025
CWE ID 362

Summary

CVE-2022-38047 is a remote code execution vulnerability affecting the Windows Point-to-Point Tunneling Protocol (PPTP). An attacker can exploit this weakness by sending specially crafted packets to a targeted system, potentially gaining unauthorized access and executing malicious code. Successful exploitation may lead to significant security risks, including unauthorized data access or system compromise. Microsoft has released a patch to address this issue, and it is recommended that all affected systems be updated promptly. Organizations should also consider disabling PPTP where possible and implementing alternative, more secure VPN protocols.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008
  • Microsoft Windows 7
  • Microsoft Windows 10
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012

Affected Vendors

  • Microsoft