7.8

CVE-2022-34713

Warning

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 10 1507 Version < 10.0.10240.19387
MicrosoftWindows 10 1607 Version < 10.0.14393.5291
MicrosoftWindows 10 1809 Version < 10.0.17763.3287
MicrosoftWindows 10 20h2 Version < 10.0.19042.1889
MicrosoftWindows 10 21h1 HwPlatformarm64 Version < 10.0.19043.1889
MicrosoftWindows 10 21h2 Version < 10.0.19044.1889
MicrosoftWindows 11 21h2 Version < 10.0.22000.856
MicrosoftWindows 7 Version- Updatesp1 HwPlatformx64
MicrosoftWindows 7 Version- Updatesp1 HwPlatformx86
MicrosoftWindows 8.1 Version- HwPlatformx64
MicrosoftWindows 8.1 Version- HwPlatformx86
MicrosoftWindows Rt 8.1 Version-
MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
MicrosoftWindows Server 2016 Version < 10.0.14393.5291
MicrosoftWindows Server 2019 Version < 10.0.17763.3287
MicrosoftWindows Server 2022 Version < 10.0.20348.887
MicrosoftWindows Server 20h2 Version < 10.0.19042.1889

09.08.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 8.23% 0.919
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
secure@microsoft.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H