CVE-2022-21971: Windows Runtime Remote Code Execution Vulnerability
Windows Runtime Remote Code Execution Vulnerability
Other sources
Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.1526Patch KB5010342 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.493Patch KB5010386 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1526Patch KB5010342 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.524Fixed in 10.0.20348.525Patch KB5010456 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1526Patch KB5010342 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.2094Patch KB5010345 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2565Patch KB5010351
Event History
Frequently Asked Questions
What is CVE-2022-21971?
CVE-2022-21971 is a vulnerability in Microsoft Windows Runtime that allows for remote code execution.
Which versions of Windows are affected by CVE-2022-21971?
Windows 10 versions 20H2, 21H1, 21H2, and Windows 11 are affected by CVE-2022-21971.
What is the severity of CVE-2022-21971?
CVE-2022-21971 has a severity rating of 7.8, which is classified as critical.
How can I fix CVE-2022-21971?
To fix CVE-2022-21971, you should apply the relevant security patch provided by Microsoft. Please refer to the provided remedy URLs for more information.
Where can I find more information about CVE-2022-21971?
You can find more information about CVE-2022-21971 on the Microsoft Security Response Center website.