Microsoft Windows Runtime(.net framework)是美国微软(Microsoft)公司的一款Windows操作系统中必要的功能支持库。 Microsoft Windows Runtime 存在缓冲区错误漏洞。以下产品和版本受到影响:Windows 10 Version 21H2 for x64-based Systems,Windows 10 Version 21H2 for ARM64-based Systems,Windows 10 Version 21H2 for 3
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Windows 10 Version 1809 | 10.0.17763.0 ~ 10.0.17763.2565 | - |
|
| Microsoft | Windows 10 Version 1809 | 10.0.0 ~ 10.0.17763.2565 | - |
|
| Microsoft | Windows Server 2019 | 10.0.17763.0 ~ 10.0.17763.2565 | - |
|
| Microsoft | Windows Server 2019 (Server Core installation) | 10.0.17763.0 ~ 10.0.17763.2565 | - |
|
| Microsoft | Windows 10 Version 1909 | 10.0.0 ~ 10.0.18363.2094 | - |
|
| Microsoft | Windows 10 Version 21H1 | 10.0.0 ~ 10.0.19043.1526 | - |
|
| Microsoft | Windows Server 2022 | 10.0.20348.0 ~ 10.0.20348.524 | - |
|
| Microsoft | Windows 10 Version 20H2 | 10.0.0 ~ 10.0.19042.1526 | - |
|
| Microsoft | Windows Server version 20H2 | 10.0.0 ~ 10.0.19042.1526 | - |
|
| Microsoft | Windows 11 version 21H2 | 10.0.0 ~ 10.0.22000.493 | - |
|
| Microsoft | Windows 10 Version 21H2 | 10.0.19043.0 ~ 10.0.19044.1526 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | PoC for CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability" | https://github.com/0vercl0k/CVE-2022-21971 | POC Details |
| 2 | None | https://github.com/tufanturhan/CVE-2022-21971-Windows-Runtime-RCE | POC Details |
| 3 | POC Of CVE-2022-21971 | https://github.com/Malwareman007/CVE-2022-21971 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-23274 | 8.8 HIGH | Microsoft Dynamics GP Remote Code Execution Vulnerability |
| CVE-2022-21984 | 8.8 HIGH | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2022-22005 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2022-23272 | 8.1 HIGH | Microsoft Dynamics GP Elevation Of Privilege Vulnerability |
| CVE-2022-23256 | 8.1 HIGH | Azure Data Explorer Spoofing Vulnerability |
| CVE-2022-21991 | 8.1 HIGH | Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability |
| CVE-2022-21987 | 8.0 HIGH | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2022-21995 | 7.9 HIGH | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2022-22004 | 7.8 HIGH | Microsoft Office ClickToRun Remote Code Execution Vulnerability |
| CVE-2022-21981 | 7.8 HIGH | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2022-21996 | 7.8 HIGH | Win32k Elevation of Privilege Vulnerability |
| CVE-2022-21999 | 7.8 HIGH | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2022-22000 | 7.8 HIGH | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2022-22001 | 7.8 HIGH | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
| CVE-2022-22003 | 7.8 HIGH | Microsoft Office Graphics Remote Code Execution Vulnerability |
| CVE-2022-21926 | 7.8 HIGH | HEVC Video Extensions Remote Code Execution Vulnerability |
| CVE-2022-22709 | 7.8 HIGH | VP9 Video Extensions Remote Code Execution Vulnerability |
| CVE-2022-22715 | 7.8 HIGH | Named Pipe File System Elevation of Privilege Vulnerability |
| CVE-2022-22718 | 7.8 HIGH | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2022-23276 | 7.8 HIGH | SQL Server for Linux Containers Elevation of Privilege Vulnerability |
Showing top 20 of 48 CVEs. View all on vendor page → →
No comments yet