CVE-2022-21984: Windows DNS Server Remote Code Execution Vulnerability
Published Feb 8, 2022
·Updated
Windows DNS Server Remote Code Execution Vulnerability
Affected Software
33 affected componentsFixes available
Microsoft Windows Server=20H2
Microsoft Windows 11=21H2
Microsoft Windows 11=21H2
Microsoft Windows Server 2022
Microsoft Windows Server 2022
Microsoft Windows 10=20H2
Microsoft Windows 10=20H2
Microsoft Windows 10=20H2
Microsoft Windows 10=21H1
Microsoft Windows 10=21H1
Microsoft Windows 10=21H1
Microsoft Windows 10=21H2
Microsoft Windows 10=21H2
Microsoft Windows 10=21H2
Microsoft Windows 10=1909
Microsoft Windows 10=1909
Microsoft Windows 10=1909
Microsoft Windows 10=20h2
Microsoft Windows 10=20h2
Microsoft Windows 10=20h2
Microsoft Windows 10=21h1
Microsoft Windows 10=21h1
Microsoft Windows 10=21h1
Microsoft Windows 10=21h2
Microsoft Windows 10=21h2
Microsoft Windows 10=21h2
Microsoft Windows 10=1909
Microsoft Windows 10=1909
Microsoft Windows 10=1909
Microsoft Windows 11
Microsoft Windows 11
Microsoft Windows Server=20h2
Microsoft Windows Server=2022
Event History
Feb 8, 2022
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Feb 9, 2022
CVE Published
via MITRE·04:36 PM
Data Sourced
via MITRE·04:36 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2022-21984?
CVE-2022-21984 has been assigned a CVSS score indicating a critical severity level due to its potential for remote code execution.
2
How do I fix CVE-2022-21984?
To fix CVE-2022-21984, you must install the relevant security updates provided by Microsoft for the affected Windows versions.
3
Which versions of Windows are affected by CVE-2022-21984?
CVE-2022-21984 affects Windows 10, Windows 11, and several versions of Windows Server.
4
Can CVE-2022-21984 be exploited remotely?
Yes, CVE-2022-21984 can be exploited remotely, allowing attackers to execute arbitrary code on vulnerable systems.
5
What are the potential consequences of an exploit for CVE-2022-21984?
Exploitation of CVE-2022-21984 may lead to full system compromise, allowing an attacker to install programs, view, change, or delete data, and create new accounts.