Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-22466

20
FAUCET Score

CVE-2023-22466 is a medium-severity vulnerability affecting Tokio, a Rust runtime, specifically versions 1.7.0 through 1.18.3, 1.19.0 through 1.20.2, and 1.21.0 through 1.23.0. It allows remote clients to access Windows named pipe servers if the pipe's associated path is on a publicly shared folder, due to an unintended reset of the reject_remote_clients setting when pipe_mode is configured. The CVSS score is 5.4 (MEDIUM) with an attack vector of network, low attack complexity, and potential for low impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code, or significant community discussion. Patches are available in Tokio versions 1.18.4, 1.20.3, 1.23.1, and all releases from 1.24.0 onwards.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.7.0, < 1.18.4CPE matchmatch criteria
cpe:2.3:a:tokio:tokio:*:*:*:*:*:rust:*:*
>= 1.19.0, < 1.20.3CPE matchmatch criteria
cpe:2.3:a:tokio:tokio:*:*:*:*:*:rust:*:*
>= 1.21.0, < 1.23.1CPE matchmatch criteria
cpe:2.3:a:tokio:tokio:*:*:*:*:*:rust:*:*

CVSS Data

CVSS version used by this source: 3.1

5.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.57%
Probability of exploitation in next 30 days
EPSS Percentile
43.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0057 is in the 54th percentile among its peer group of 21,977 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (30)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 19864-17084Fixed in: 1.10.3-1
microsoftpatch availablevia msrc
Product: 18012-16823Fixed in: 1.0.3-5
microsoftpatch availablevia msrc
Product: 18013-16823Fixed in: 3.1.0-11
microsoftpatch availablevia msrc
Product: 19706-17084Fixed in: 3.2.0.azl0-2
microsoftpatch availablevia msrc
Product: azl3 rpm-ostree 2022.1-7 on Azure Linux 3.0Fixed in: 2024.4-1
microsoftpatch availablevia msrc
Product: cm1 rust 1.59.0-1 on CBL Mariner 1.0Fixed in: 1.59.0-1
microsoftpatch availablevia msrc
Product: cbl2 rust 1.68.2-5 on CBL Mariner 2.0Fixed in: 1.68.2-5
microsoftpatch availablevia msrc
Product: cbl2 rpm-ostree 2022.1-7 on CBL Mariner 2.0Fixed in: 2022.1-7
microsoftpatch availablevia msrc
Product: cbl2 netavark 1.0.3-5 on CBL Mariner 2.0Fixed in: 1.0.3-5
microsoftpatch availablevia msrc
Product: cbl2 kata-containers 3.1.0-11 on CBL Mariner 2.0Fixed in: 3.1.0-11
microsoftpatch availablevia msrc
Product: azl3 kata-containers 3.1.3-2 on Azure Linux 3.0Fixed in: 3.2.0.azl0-2
microsoftpatch availablevia msrc
Product: azl3 netavark 1.0.3-5 on Azure Linux 3.0Fixed in: 1.10.3-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 3.2.0.azl0-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 1.72.0-2
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 3.2.0.azl0-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 1.72.0-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 3.2.0.azl0-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 1.10.3-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 2024.4-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 3.2.0.azl0-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 1.10.3-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 2024.4-1
microsoftpatch availablevia msrc
Product: 18815-17084Fixed in: 2024.4-1
microsoftpatch availablevia msrc
Product: 17941-16820Fixed in: 1.59.0-1
microsoftpatch availablevia msrc
Product: 17944-16823Fixed in: 1.68.2-5
microsoftpatch availablevia msrc
Product: 18011-16823Fixed in: 2022.1-7
rustpatch availablevia ghsa
Product: tokioFixed in: 1.23.1
rustpatch availablevia ghsa
Product: tokioFixed in: 1.20.3
rustpatch availablevia ghsa
Product: tokioFixed in: 1.18.4

Vendor Advisories (3)

microsoft2024-Jun/CVE-2023-22466

CVE-2023-22466

Jun 11, 2024
microsoft2023-Jan/CVE-2023-22466Moderate

Tokio's reject_remote_clients configuration may get dropped when creating a Windows named pipe

Jan 10, 2023
rustGHSA-7rrj-xr53-82p7medium

Tokio reject_remote_clients configuration may get dropped when creating a Windows named pipe

Jan 6, 2023

References

github.com / tokio-rs/tokio/pull/5336
PatchThird Party Advisory
github.com / tokio-rs/tokio/releases/tag/tokio-1.23.1
Release NotesThird Party Advisory
github.com / tokio-rs/tokio/security/advisories/GHSA-7rrj-xr53-82p7
MitigationThird Party Advisory
learn.microsoft.com / en-us/windows/win32/api/winbase/nf-winbase-createnamedpipea
Technical DescriptionThird Party Advisory