Critical RCE Vulnerability in Windows Remote Procedure Call Runtime
Microsoft security updates address a critical RCE vulnerability in Remote Procedure Call Runtime affecting multiple products
Summary
Microsoft security updates address a critical RCE vulnerability in Remote Procedure Call Runtime affecting multiple products
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Microsoft has released security updates to fix a vulnerability tracked as CVE-2022-26809 with a CVSS v3.1 severity rating of 9.8 (Critical), which affects multiple Windows platforms. The vulnerability was addressed as part of Microsoft's April 2022 Security Update. CVE-2022-26809 could be exploited to allow an unauthenticated attacker to perform remote code execution (RCE) on the system.
Vulnerability details
CVE-2022-26809 is a vulnerability in Remote Procedure Call (RPC) Runtime. RPC Runtime is used in multiple Windows platforms to manage processes relating to network communication in distributed client-server programs.
An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted RPC call to an RPC host. Successful exploitation of CVE-2022-26809 could result in remote code execution on the server side with the same permissions as the RPC service.
Microsoft assess that this vulnerability has a low attack complexity, and requires no user interaction and no privileges. These features could potentially make the vulnerability wormable, although this has not been confirmed by Microsoft at the time of publication.
Apply security updates urgently
Proof of concept (PoC) code is expected to progress to weaponisation and exploitation rapidly, therefore organisations are urged to apply security updates as a matter of urgency.
Remediation advice
Affected organisations are required to review Microsoft's April 2022 Security Update Summary and Deployment Information and apply the relevant patches. Further details on this vulnerability can be found in Microsoft's Update Guide for CVE-2022-26809.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 14 April 2022 10:47 am