CVE-2022-41039: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23968Patch KB5020003 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20671Fixed in 6.3.9600.20670Patch KB5020010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26221Patch KB5020013 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20670Patch KB5020010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5501Patch KB5019964 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19567Patch KB5019970 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.819Patch KB5019980 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.1219Patch KB5019961 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1249Fixed in 10.0.20348.1251Patch KB5019080 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.3650Patch KB5019966
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41039?
CVE-2022-41039 is classified as a critical vulnerability that allows remote code execution in Windows Point-to-Point Tunneling Protocol.
How do I fix CVE-2022-41039?
To fix CVE-2022-41039, ensure you apply the latest security updates from Microsoft that address this vulnerability.
What products are affected by CVE-2022-41039?
CVE-2022-41039 affects multiple Microsoft products including various versions of Windows 10, Windows 11, and Windows Server 2022.
Can CVE-2022-41039 be exploited remotely?
Yes, CVE-2022-41039 can be exploited remotely by an attacker to execute arbitrary code on affected systems.
What recommendations are there for mitigating the risk of CVE-2022-41039?
In addition to applying patches, it is recommended to limit exposure to the affected services and implement proper firewall rules.