First published: Tue Dec 13 2022(Updated: )
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 7 | ||
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows 7 | ||
Microsoft Windows RT | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows 8.1 | ||
Microsoft Windows 8.1 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2019 | ||
Windows 11 | =22H2 | |
Windows 11 | =22H2 | |
Windows 11 | =21H2 | |
Windows 11 | =21H2 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | ||
Windows 10 | =20H2 | |
Windows 10 | =20H2 | |
Windows 10 | =1809 | |
Windows 10 | =1809 | |
Windows 10 | =1809 | |
Windows 10 | =22H2 | |
Windows 10 | =22H2 | |
Windows 10 | =22H2 | |
Windows 10 | =1607 | |
Windows 10 | =1607 | |
Windows 10 | =21H1 | |
Windows 10 | =21H1 | |
Windows 10 | =21H1 | |
Windows 10 | =21H2 | |
Windows 10 | =21H2 | |
Windows 10 | =21H2 | |
Windows 10 | ||
Windows 10 | ||
Windows 10 | ||
Windows 10 | =20h2 | |
Windows 10 | =21h1 | |
Windows 10 | =21h2 | |
Windows 10 | =22h2 | |
Windows 10 | =1607 | |
Windows 10 | =1809 | |
Windows 11 | ||
Windows 11 | =22h2 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2022 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44670 has been classified with a critical severity level due to its potential for remote code execution.
To remediate CVE-2022-44670, apply the appropriate security patches provided by Microsoft for the affected Windows products.
CVE-2022-44670 affects various versions of Windows, including Windows 10, Windows 11, Windows Server 2022, and older versions like Windows 7 and Windows Server 2008.
While the best practice is to apply the patches, temporary mitigations may involve restricting SSTP connections until updates can be applied.
Yes, Microsoft has released specific updates, including KB5021249, KB5021233, and others, to address CVE-2022-44670.