Critical RCE Vulnerability in Microsoft Windows Internet Key Exchange (IKE) Protocol Extensions
Microsoft security updates addressed a remote code execution vulnerability in IKE Protocol Extensions
Summary
Microsoft security updates addressed a remote code execution vulnerability in IKE Protocol Extensions
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Microsoft has released details of a critical remote code execution vulnerability, known as CVE-2022-34721, in the September 2022 security updates. This vulnerability has a CVSSv3 score of 9.8.
CVE-2022-34721 relates to Windows Internet Key Exchange (IKE) Protocol Extensions and an unauthenticated, remote attacker could send a specially crafted IP packet to a target machine that is running Windows and has IPSec enabled, which could enable a remote code execution exploitation.
Proof-of-concept and Exploitation in the wild for CVE-2022-34721
Security researchers have released a proof-of-concept (PoC) code and exploitation has been reported in the wild.
Threat updates
| Date | Update |
|---|---|
| 30 Nov 2022 |
Exploitation
This Cyber Alert has been updated to reflect that there has been exploitation in the wild reported. |
Remediation advice
Affected organisations are required to read Microsoft's guidance on the Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability CVE-2022-34721 and apply the relevant updates as soon as practicable.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 30 November 2022 2:47 pm