First published: Tue Jan 11 2022(Updated: )
HTTP Protocol Stack Remote Code Execution Vulnerability.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 10 | =20h2 | |
Microsoft Windows 10 | =20h2 | |
Microsoft Windows 10 | =20h2 | |
Microsoft Windows 10 | =21h1 | |
Microsoft Windows 10 | =21h1 | |
Microsoft Windows 10 | =21h1 | |
Microsoft Windows 10 | =21h2 | |
Microsoft Windows 10 | =21h2 | |
Microsoft Windows 10 | =21h2 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 11 | ||
Microsoft Windows 11 | ||
Microsoft Windows Server | =20h2 | |
Microsoft Windows Server | =2022 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows 10 | =1809 | |
Microsoft Windows 11 | =21H2 | |
Microsoft Windows 10 | =21H1 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 10 | =20H2 | |
Microsoft Windows 10 | =21H1 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows 10 | =21H1 | |
Microsoft Windows Server | =20H2 | |
Microsoft Windows 10 | =20H2 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows 10 | =1809 | |
Microsoft Windows 11 | =21H2 | |
Microsoft Windows 10 | =21H2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21907 has a critical severity level as it allows remote code execution through the HTTP Protocol Stack.
To mitigate CVE-2022-21907, apply the required security patches provided by Microsoft, specifically KB5009543, KB5009555, KB5009557, or KB5009566 based on your system version.
CVE-2022-21907 affects multiple versions of Microsoft Windows 10, Windows 11, and Windows Server, including versions 1809, 20H2, 21H1, and 21H2.
Currently, the primary method for addressing CVE-2022-21907 is to install the latest patches, as there are no noted workarounds.
CVE-2022-21907 could potentially allow an attacker to execute arbitrary code on the affected system, leading to unauthorized access or control.