Input validation error in Microsoft products - CVE-2022-22017
Published: May 10, 2022
Vulnerability identifier: #VU62980
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22017
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input in Remote Desktop Client. A remote attacker can trick a victim to connect to a malicious RDP server and execute arbitrary code on the target system.
Affected software
Remote Desktop client for Windows Desktop
Microsoft Windows
Windows Server
Microsoft Windows
Windows Server
How to mitigate CVE-2022-22017
Install updates from vendor's website.