CVE-2022-41056: Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability
Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23968Patch KB5020003 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21768Patch KB5020005 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20671Fixed in 6.3.9600.20670Patch KB5020010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26221Patch KB5020013 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5501Patch KB5019964 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20670Patch KB5020010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19567Patch KB5019970 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.819Patch KB5019980 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.1219Patch KB5019961 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1249Fixed in 10.0.20348.1251Patch KB5019080 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.3650Patch KB5019966
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41056?
CVE-2022-41056 has a critical severity rating due to its potential to allow denial of service attacks via the RADIUS protocol.
How do I fix CVE-2022-41056?
To fix CVE-2022-41056, apply the latest security updates available for your affected Microsoft products.
What products are affected by CVE-2022-41056?
CVE-2022-41056 affects various Microsoft products including Windows Server 2008 R2, Windows 10, Windows 11, and Windows Server 2022.
Can CVE-2022-41056 be exploited remotely?
Yes, CVE-2022-41056 can be exploited remotely, making it particularly dangerous if not mitigated promptly.
What kind of impact does CVE-2022-41056 have on systems?
CVE-2022-41056 could lead to denial of service, causing systems to become unresponsive and affecting network availability.