1 min read

CVE-2022-21907: New Wormable Vulnerability in Microsoft Windows

CVE-2022-21907: New Wormable Vulnerability in Microsoft Windows

Included in the latest “Patch Tuesday” from Microsoft on January 11, 2022, is a fix for CVE-2022-21907 (CVSS3.1 9.8).

Per Microsoft, this is a remote code execution vulnerability in the HTTP protocol stack. Exploitation of this vulnerability requires no user interaction and is wormable. All versions of Windows 10 version 1809 and above, including Windows Server 2019 and Windows Server 2022 are vulnerable. No exploits have been seen in the wild (yet), but the likelihood of exploitation is extremely high.

Remediation

The latest cumulative patch from Microsoft fixes this vulnerability. Simply install the patch and restart the system.

If patching and restarting servers is not a viable option, there is a quickfix:

In Windows Server 2019 and Windows 10 version 1809, the HTTP Trailer Support feature that contains the vulnerability is not active by default. The following registry key must be configured to introduce the vulnerable condition:

   HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters\

   “EnableTrailerSupport”=dword:00000001

Resources

Cyber Threat Intelligence Report

9 min read

Cyber Threat Intelligence Report

This week, we briefed our clients on recent data extortion campaigns targeting numerous industry verticals with fake technical support vishing...

Read More
Cyber Threat Intelligence Report

6 min read

Cyber Threat Intelligence Report

This week, we briefed our clients on "Certighost", a Domain Controller Impersonation Exploit that allows standard users to obtain valid DC...

Read More
Cyber Threat Intelligence Report

7 min read

Cyber Threat Intelligence Report

This week, we briefed our clients on details of the Progress ShareFile shutdown on Friday, July 10th, and other vulnerabilities from the past two...

Read More
Future Team Sixty43 Reports.
Be notified when Cyber Threat Intelligence Reports, Threat Profiles, or Beyond the Threat Feed articles are published.