5.9

CVE-2022-41090

Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftWindows 10 Version-
MicrosoftWindows 10 Version20h2
MicrosoftWindows 10 Version21h1
MicrosoftWindows 10 Version21h2
MicrosoftWindows 10 Version22h2
MicrosoftWindows 10 Version1607
MicrosoftWindows 10 Version1809
MicrosoftWindows 11 Version- HwPlatformarm64
MicrosoftWindows 11 Version- HwPlatformx64
MicrosoftWindows 11 Version22h2 HwPlatformarm64
MicrosoftWindows 11 Version22h2 HwPlatformx64
MicrosoftWindows 7 Version- Updatesp1
MicrosoftWindows 8.1 Version-
MicrosoftWindows 8.1 Version- SwEditionrt
MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
MicrosoftWindows Server 2022 Version- SwEditiondatacenter:_azure
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.586
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
secure@microsoft.com 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.