First published: Tue May 10 2022(Updated: )
Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-23270.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server | =20H2 | |
Microsoft Windows 7 | ||
Microsoft Windows 7 | ||
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows RT | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows 8.1 | ||
Microsoft Windows 8.1 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2019 | ||
Windows 11 | =21H2 | |
Windows 11 | =21H2 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | ||
Windows 10 | =20H2 | |
Windows 10 | =20H2 | |
Windows 10 | =1809 | |
Windows 10 | =1809 | |
Windows 10 | =1809 | |
Windows 10 | =1607 | |
Windows 10 | =1607 | |
Windows 10 | =21H1 | |
Windows 10 | =21H1 | |
Windows 10 | =21H1 | |
Windows 10 | =21H2 | |
Windows 10 | =21H2 | |
Windows 10 | =21H2 | |
Windows 10 | =1909 | |
Windows 10 | =1909 | |
Windows 10 | =1909 | |
Windows 10 | ||
Windows 10 | ||
Windows 10 | ||
Windows 10 | =20h2 | |
Windows 10 | =21h1 | |
Windows 10 | =21h2 | |
Windows 10 | =1607 | |
Windows 10 | =1809 | |
Windows 10 | =1909 | |
Windows 11 | ||
Windows 11 | ||
Microsoft Windows 7 | =sp1 | |
Microsoft Windows | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =20h2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2022 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21972 has a critical severity rating as it allows for remote code execution via the Point-to-Point Tunneling Protocol.
To fix CVE-2022-21972, apply the appropriate patches released by Microsoft for affected versions of Windows.
CVE-2022-21972 impacts various Windows versions, including Windows 10, Windows 11, and several Windows Server editions.
An attacker could exploit CVE-2022-21972 to execute arbitrary code on the target system, potentially gaining full control.
While it is recommended to patch promptly, temporary network isolation of affected systems may mitigate risks until updates can be applied.