CVE-2022-34713: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application.
Other sources
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20520Patch KB5016683 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26065Patch KB5016679 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23817Patch KB5016684 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20520Patch KB5016681 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5291Patch KB5016622 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19387Patch KB5016639 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.1889Patch KB5016616 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.856Patch KB5016629 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1889Patch KB5016616 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1889Patch KB5016616 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.887Patch KB5016627 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.3287Patch KB5016623
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34713?
CVE-2022-34713 has a critical severity rating, indicating a significant risk for remote code execution.
How do I fix CVE-2022-34713?
To mitigate the risk of CVE-2022-34713, install the recommended security patches provided by Microsoft for the affected Windows versions.
Which versions of Windows are affected by CVE-2022-34713?
CVE-2022-34713 affects multiple Windows versions, including Windows 10, Windows 11, and various Windows Server editions.
What type of vulnerability is CVE-2022-34713?
CVE-2022-34713 is classified as a remote code execution vulnerability impacting the Microsoft Windows Support Diagnostic Tool.
Can exploiting CVE-2022-34713 compromise my system?
Yes, successful exploitation of CVE-2022-34713 could allow attackers to run arbitrary code on the affected system, potentially leading to a full compromise.