CVE-2022-22002

Description

Windows User Account Profile Picture Denial of Service Vulnerability

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.273

Associated Vulnerability

VulnerabilityOS Platform
Windows Runtime Remote Code Execution Vulnerability for Windows 10 Version 21H1 for x64-based Systems (KB5010342) (CVE-2022-21989)Windows
Windows Runtime Remote Code Execution Vulnerability for Windows 10 Version 21H2 for x86-based Systems (KB5010342) (CVE-2022-21989)Windows
Windows Runtime Remote Code Execution Vulnerability for Windows 10 Version 21H2 for x64-based Systems (KB5010342) (CVE-2022-21989)Windows
Windows Runtime Remote Code Execution Vulnerability for Windows 10 Version 21H1 for x86-based Systems (KB5010342) (CVE-2022-21989)Windows
Windows Runtime Remote Code Execution Vulnerability for Windows 10 Version 20H2 for x86-based Systems (KB5010342) (CVE-2022-21989)Windows
Windows Runtime Remote Code Execution Vulnerability for Windows 10 Version 20H2 for x64-based Systems (KB5010342) (CVE-2022-21989)Windows
Windows Runtime Remote Code Execution Vulnerability for Windows 10 Version 1909 for x86-based Systems (KB5010345) (CVE-2022-21989)Windows
Windows Runtime Remote Code Execution Vulnerability for Windows 10 Version 1909 for x64-based Systems (KB5010345) (CVE-2022-21989)Windows
Windows Runtime Remote Code Execution Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB5010351) (CVE-2022-21989)Windows
Windows Runtime Remote Code Execution Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB5010351) (CVE-2022-21989)Windows
Windows Runtime Remote Code Execution Vulnerability for Windows Server 2019 for x64-based Systems (KB5010351) (CVE-2022-21989)Windows
Windows Runtime Remote Code Execution Vulnerability for Microsoft server operating system version 21H2 for x64-based Systems (KB5010354) (CVE-2022-21989)Windows
Windows Runtime Remote Code Execution Vulnerability for Windows 11 for x64-based Systems (KB5010386) (CVE-2022-21989)Windows
Roaming Security Rights Management Services Remote Code Execution Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB5010359) (CVE-2022-21989)Windows
Roaming Security Rights Management Services Remote Code Execution Vulnerability for Windows Server 2016 for x64-based Systems (KB5010359) (CVE-2022-21989)Windows
Roaming Security Rights Management Services Remote Code Execution Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB5010359) (CVE-2022-21989)Windows
Windows Common Log File System Driver Elevation of Privilege Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB5010358) (CVE-2022-21989)Windows
Windows Common Log File System Driver Elevation of Privilege Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB5010358) (CVE-2022-21989)Windows
Windows Common Log File System Driver Elevation of Privilege Vulnerability for Windows 8.1 for x86-based Systems (KB5010395) (CVE-2022-21989)Windows
Windows Common Log File System Driver Elevation of Privilege Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB5010395) (CVE-2022-21989)Windows
Windows Common Log File System Driver Elevation of Privilege Vulnerability for Windows 8.1 for x64-based Systems (KB5010395) (CVE-2022-21989)Windows
Windows Common Log File System Driver Elevation of Privilege Vulnerability for Windows Server 2008 for x64-based Systems (KB5010403) (ESU) (CVE-2022-21989)Windows
Windows Common Log File System Driver Elevation of Privilege Vulnerability for Windows Server 2008 for x86-based Systems (KB5010403) (ESU) (CVE-2022-21989)Windows
Windows Common Log File System Driver Elevation of Privilege Vulnerability for Windows Server 2012 for x64-based Systems (KB5010412) (CVE-2022-21989)Windows
Windows Common Log File System Driver Elevation of Privilege Vulnerability for Windows 8.1 for x86-based Systems (KB5010419) (CVE-2022-21989)Windows
Windows Common Log File System Driver Elevation of Privilege Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB5010419) (CVE-2022-21989)Windows
Windows Common Log File System Driver Elevation of Privilege Vulnerability for Windows 8.1 for x64-based Systems (KB5010419) (CVE-2022-21989)Windows
Windows Print Spooler Elevation of Privilege Vulnerability for Windows Server 2012 for x64-based Systems (KB5010392)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-330502022-02 Cumulative Update for Windows 10 Version 21H1 for x64-based Systems (KB5010342) (CVE-2022-21989)
PATCH-330512022-02 Cumulative Update for Windows 10 Version 21H2 for x86-based Systems (KB5010342) (CVE-2022-21989)
PATCH-330522022-02 Cumulative Update for Windows 10 Version 21H2 for x64-based Systems (KB5010342) (CVE-2022-21989)
PATCH-330532022-02 Cumulative Update for Windows 10 Version 21H1 for x86-based Systems (KB5010342) (CVE-2022-21989)
PATCH-330542022-02 Cumulative Update for Windows 10 Version 20H2 for x86-based Systems (KB5010342) (CVE-2022-21989)
PATCH-330552022-02 Cumulative Update for Windows 10 Version 20H2 for x64-based Systems (KB5010342) (CVE-2022-21989)
PATCH-330592022-02 Cumulative Update for Windows 10 Version 1909 for x86-based Systems (KB5010345) (CVE-2022-21989)
PATCH-330602022-02 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB5010345) (CVE-2022-21989)
PATCH-330612022-02 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB5010351) (CVE-2022-21989)
PATCH-330622022-02 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB5010351) (CVE-2022-21989)
PATCH-330632022-02 Cumulative Update for Windows Server 2019 for x64-based Systems (KB5010351) (CVE-2022-21989)
PATCH-330582022-02 Cumulative Update for Microsoft server operating system version 21H2 for x64-based Systems (KB5010354) (CVE-2022-21989)
PATCH-330572022-02 Cumulative Update for Windows 11 for x64-based Systems (KB5010386) (CVE-2022-21989)
PATCH-330452022-02 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB5010359) (CVE-2022-21989)
PATCH-330462022-02 Cumulative Update for Windows Server 2016 for x64-based Systems (KB5010359) (CVE-2022-21989)
PATCH-330472022-02 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB5010359) (CVE-2022-21989)
PATCH-330482022-02 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB5010358) (CVE-2022-21989)
PATCH-330492022-02 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB5010358) (CVE-2022-21989)
PATCH-330362022-02 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB5010395) (CVE-2022-21989)
PATCH-330372022-02 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB5010395) (CVE-2022-21989)
PATCH-330382022-02 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB5010395) (CVE-2022-21989)
PATCH-330392022-02 Security Only Quality Update for Windows Server 2008 for x64-based Systems (KB5010403) (ESU) (CVE-2022-21989)
PATCH-330402022-02 Security Only Quality Update for Windows Server 2008 for x86-based Systems (KB5010403) (ESU) (CVE-2022-21989)
PATCH-330412022-02 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB5010412) (CVE-2022-21989)
PATCH-330642022-02 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB5010419) (CVE-2022-21989)
PATCH-330652022-02 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB5010419) (CVE-2022-21989)
PATCH-330662022-02 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB5010419) (CVE-2022-21989)
PATCH-330672022-02 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB5010392)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234