Last Modified: March 10, 2023
Windows Contacts Remote Code Execution Vulnerability
Tweets last week: 0
Remaining steady
Yahoo results: 186000
Remaining steady
Current EPSS Score: 0.00316
Remaining steady
Reddit Posts: 0
Remaining steady
Github Repos: 1
Remaining steady
Found exploits:
Attack Vector: Local
Attack Complexity: Low
Privileges Required: None
User Interaction: Required
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Base Score: 7.8
Exploitability Score:
1.8
Impact Score: 5.9
CVSS V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NVD-CWE-noinfo
Condition | Configuration | |
---|---|---|
OR | ||
OR | ||
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:x64:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_11:22h2:*:*:*:*:*:x64:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft | |
cpe:2.3:o:microsoft:windows_10:22h2:*:*:*:*:*:*:* Part: o Vendor: microsoft | Alle Schwachstellen für microsoft |
CWE-ID:
Not defined
Configuration:
added:
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11:22h2:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10:22h2:*:*:*:*:*:*:*
Reference:
added:
http://packetstormsecurity.com/files/171047/Microsoft-Windows-Contact-File-Remote-Code-Execution.html
Reference:
added:
http://seclists.org/fulldisclosure/2023/Feb/14
Description:
Windows Contacts Remote Code Execution Vulnerability.
Reference:
added:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-44666
removed:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-44666
http://packetstormsecurity.com/files/171047/Microsoft-Windows-Contact-File-Remote-Code-Execution.html
http://seclists.org/fulldisclosure/2023/Feb/14
<?xml version="1.0" ?> <set operator="and"> <set operator="or"> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:x64:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_11:22h2:*:*:*:*:*:x64:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_10:22h2:*:*:*:*:*:*:*"/> </set> </set>
<?xml version="1.0" ?> <set operator="and"> <set operator="or"> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:x64:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:*:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_11:22h2:*:*:*:*:*:x64:*"/> <prop key="operating_system" value="cpe:2.3:o:microsoft:windows_10:22h2:*:*:*:*:*:*:*"/> </set> <prop key="program_influence" value="input"/> </set>