CVE-2022-22017 is a Remote Code Execution vulnerability affecting Microsoft Remote Desktop Client, Windows 11, and Windows Server 2022. With a CVSS score of 8.8 (HIGH), it allows an unauthenticated attacker to execute arbitrary code remotely with low attack complexity, potentially leading to full compromise of the affected system. While there is no evidence of active exploitation (KEV) or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness. Organizations should prioritize patching due to the high potential impact if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:remote_desktop_client:-:*:*:*:*:windows:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:arm64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:x64:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.