1 min read

CVE-2022-21907: New Wormable Vulnerability in Microsoft Windows

CVE-2022-21907: New Wormable Vulnerability in Microsoft Windows

Included in the latest “Patch Tuesday” from Microsoft on January 11, 2022, is a fix for CVE-2022-21907 (CVSS3.1 9.8).

Per Microsoft, this is a remote code execution vulnerability in the HTTP protocol stack. Exploitation of this vulnerability requires no user interaction and is wormable. All versions of Windows 10 version 1809 and above, including Windows Server 2019 and Windows Server 2022 are vulnerable. No exploits have been seen in the wild (yet), but the likelihood of exploitation is extremely high.

Remediation

The latest cumulative patch from Microsoft fixes this vulnerability. Simply install the patch and restart the system.

If patching and restarting servers is not a viable option, there is a quickfix:

In Windows Server 2019 and Windows 10 version 1809, the HTTP Trailer Support feature that contains the vulnerability is not active by default. The following registry key must be configured to introduce the vulnerable condition:

   HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters\

   “EnableTrailerSupport”=dword:00000001

Resources

Cyber Threat Intelligence Report

7 min read

Cyber Threat Intelligence Report

This week, we briefed our clients on details of the Progress ShareFile shutdown on Friday, July 10th, and other vulnerabilities from the past two...

Read More
Cyber Threat Intelligence Report

6 min read

Cyber Threat Intelligence Report

This week, we briefed our clients on details of the widespread FortiBleed credential compromise and the breach that exposed data from the LastPass...

Read More
Cyber Threat Intelligence Report

8 min read

Cyber Threat Intelligence Report

This week, we briefed our clients on the new Ghost-sender Email Spoofing research from InfoGuard Labs. Be sure to test your domain for the...

Read More
Future Team Sixty43 Reports.
Be notified when Cyber Threat Intelligence Reports, Threat Profiles, or Beyond the Threat Feed articles are published.