Code Injection in Microsoft Windows and Windows Server - CVE-2022-26809
Published: April 12, 2022 / Updated: June 19, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in Remote Procedure Call Runtime. A remote attacker can send a specially crafted RPC call to an RPC host and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Windows Server
How to mitigate CVE-2022-26809
Links to Public Exploits and PoC-codes
- Exploit #8050 - PoC-CVE-2022-26809 (PoC for CVE-2022-26809, analisys and considerations are shown in the github.io.) (June 19, 2022)
- Exploit #7670 - CVE-2022-26809-RCE (This repository contains a PoC for remote code execution CVE-2022-26809) (April 21, 2022)
- Exploit #7657 - CVE-2022-26809 () (April 15, 2022)
- Exploit #7650 - CVE-2022-26809 (CVE-2022-26809-RCE-EXP-POC) (April 15, 2022)
- Exploit #7649 - CVE-2022-26809 (Remote Code Execution Exploit in the RPC Library) (April 15, 2022)
- Exploit #7647 - CVE-2022-26809-RCE () (April 15, 2022)