Critical CVSS 9.8 EPSS 0.75711 🔬 Patch diffed 2022-09 archive

Executive Summary

None

Overview

9.8
CVSS CRITICAL
Critical
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Remote Code Execution
Released Sep 13 2022
Last Updated Sep 13 2022
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.75711 — 0.99469 percentile
NVD CVSS 9.8 CRITICAL — matches MSRC

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 8.5

EPSS Score

0.75711
probability of exploitation in the next 30 days
0.99469 percentile - updated 2026-07-25
View on FIRST.org

Affected Products

22 affected products
Product KB Article Severity Impact Restart Required
Windows 10 for 32-bit Systems 5017327 (Security Update) Critical Remote Code Execution Yes
Windows 10 for x64-based Systems 5017327 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 1607 for 32-bit Systems 5017305 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 1607 for x64-based Systems 5017305 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 1809 for 32-bit Systems 5017315 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 1809 for ARM64-based Systems 5017315 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 1809 for x64-based Systems 5017315 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 20H2 for 32-bit Systems 5017308 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 20H2 for ARM64-based Systems 5017308 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 21H1 for 32-bit Systems 5017308 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 21H1 for ARM64-based Systems 5017308 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 21H1 for x64-based Systems 5017308 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 21H2 for 32-bit Systems 5017308 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 21H2 for ARM64-based Systems 5017308 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 21H2 for x64-based Systems 5017308 (Security Update) Critical Remote Code Execution Yes
Windows 11 version 21H2 for ARM64-based Systems 5017328 (Security Update) Critical Remote Code Execution Yes
Windows 11 version 21H2 for x64-based Systems 5017328 (Security Update) Critical Remote Code Execution Yes
Windows 7 for 32-bit Systems Service Pack 1 5017361 (Monthly Rollup) 5017373 (Security Only) Critical Remote Code Execution 5016676 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26115 Yes 5017361 5017373 Windows 7 for x64-based Systems Service Pack 1 5017361 (Monthly Rollup) 5017373 (Security Only) Critical Remote Code Execution 5016676 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26115 Yes 5017361 5017373 Windows 8.1 for 32-bit systems 5017367 (Monthly Rollup) 5017365 (Security Only) Critical Remote Code Execution 5016681 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20571 Yes 5017367 5017365 Windows 8.1 for x64-based systems 5017367 (Monthly Rollup) 5017365 (Security Only) Critical Remote Code Execution 5016681 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20571 Yes 5017367 5017365 Windows RT 8.1 5017367 (Monthly Rollup) Critical Remote Code Execution Yes
Windows Server 2008 for 32-bit Systems Service Pack 2 5017358 (Monthly Rollup) 5017371 (Security Only) Critical Remote Code Execution 5016669 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21666 Yes 5017358 5017371 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5017358 (Monthly Rollup) 5017371 (Security Only) Critical Remote Code Execution 5016669 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21666 Yes 5017358 5017371 Windows Server 2008 for x64-based Systems Service Pack 2 5017358 (Monthly Rollup) 5017371 (Security Only) Critical Remote Code Execution 5016669 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21666 Yes 5017358 5017371 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5017358 (Monthly Rollup) 5017371 (Security Only) Critical Remote Code Execution 5016669 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21666 Yes 5017358 5017371 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5017361 (Monthly Rollup) 5017373 (Security Only) Critical Remote Code Execution 5016676 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26115 Yes 5017361 5017373 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5017361 (Monthly Rollup) 5017373 (Security Only) Critical Remote Code Execution 5016676 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26115 Yes 5017361 5017373 Windows Server 2012 5017370 (Monthly Rollup) 5017377 (Security Only) Critical Remote Code Execution 5016672 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.2.9200.23865 Yes 5017370 5017377 Windows Server 2012 (Server Core installation) 5017370 (Monthly Rollup) 5017377 (Security Only) Critical Remote Code Execution 5016672 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.2.9200.23865 Yes 5017370 5017377 Windows Server 2012 R2 5017367 (Monthly Rollup) 5017365 (Security Only) Critical Remote Code Execution 5016681 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20571 Yes 5017367 5017365 Windows Server 2012 R2 (Server Core installation) 5017367 (Monthly Rollup) 5017365 (Security Only) Critical Remote Code Execution 5016681 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20571 Yes 5017367 5017365 Windows Server 2016 5017305 (Security Update) Critical Remote Code Execution Yes
Windows Server 2016 (Server Core installation) 5017305 (Security Update) Critical Remote Code Execution Yes
Windows Server 2019 5017315 (Security Update) Critical Remote Code Execution Yes
Windows Server 2019 (Server Core installation) 5017315 (Security Update) Critical Remote Code Execution Yes

Patches

6 patches
Article Type Restart
5017327 Security Update Yes
5017305 Security Update Yes
5017315 Security Update Yes
5017308 Security Update Yes
5017328 Security Update Yes
5017367 Monthly Rollup Yes

Patch Diff

ghidriff · ikeext.dll (KB5017328)

Patch diff 10.0.22000.708 -> 10.0.22000.978 (IKEv1 packet decrypt/verify path hardening)

Pre-patch version 10.0.22000.708
Post-patch version 10.0.22000.978
Function Address Change Note
WS2_32.DLL::ntohl EXTERNAL:000000ef refcount similarity 1.0
IkeDecryptOakNDPacket 180096b80 -> 180096920 code, length, address, called similarity 0.14
TraceLogHelper 180043bc4 -> 180043824 refcount, address similarity 1.0
_tlgKeywordOn 1800011f8 refcount, calling similarity 1.0
_tlgCreate1Sz_wchar_t 18000112c refcount, calling similarity 1.0
IkeParseRecvAncillaryInfo 180036b30 -> 180036740 code, length, address similarity 0.81
API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapSize EXTERNAL:000000c1 refcount, calling similarity 1.0
API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapAlloc EXTERNAL:000000c0 refcount, calling similarity 1.0
IkeQueueRecvRequest 18003e6d8 -> 18003e2e8 code, refcount, length, address, calling, called similarity 0.16
API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::TrySubmitThreadpoolCallback EXTERNAL:000000d8 refcount, calling similarity 1.0
WfpReportSysErrorAsNtStatus 18004dc10 -> 18004da00 refcount, address, calling similarity 1.0
IkeAddrSetAddrBytes 18003bf70 -> 18003bb80 refcount, address, calling similarity 1.0
API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError EXTERNAL:00000035 refcount, calling similarity 1.0
memcpy 18004bee2 -> 18004bcd2 refcount, address, calling similarity 0.89
IkeReceiveCallback 1800357d0 code, length, sig, called similarity 0.09
WfpReportAppErrorAsWinError 180042788 -> 1800423e8 refcount, address, calling similarity 1.0
WfpMemFree 180030420 refcount, calling similarity 1.0
_tlgCreate1Sz_char 1800010f8 refcount, calling similarity 1.0
IkeVerifyIncomingDataSize 1800401a8 -> 18003fb7c refcount, address, calling similarity 1.0
WS2_32.DLL::htons EXTERNAL:000000f0 refcount similarity 1.0
WfpReportError 18002a060 refcount, calling similarity 1.0
IkeGetTlsPeerAddr 180044610 -> 180044270 refcount, address, calling similarity 1.0
IkeVerifyPacketHeader 180036340 -> 180035f50 code, length, sig, address, called similarity 0.18
NTDLL.DLL::EtwTraceMessage EXTERNAL:0000004c refcount, calling similarity 1.0
IkeDecryptOakPacket 180096cbc -> 180096bf4 code, length, address, called similarity 0.18
IkeHandleRecvRequest 18003b4d0 -> 18003b0e0 refcount, address similarity 1.0
_tlgWriteTransfer_EtwEventWriteTransfer 180001224 refcount, calling similarity 1.0
IkeCopyIncomingData 18004013c -> 18003fb10 refcount, address, calling similarity 1.0
IkeQueueWorkItemHiPri 1800691ac -> 180068f4c refcount, address, calling similarity 0.98
__security_check_cookie 180041460 -> 1800410c0 refcount, address, calling similarity 1.0
IkeGetTlsMmLuid 1800532fc -> 1800530ec refcount, address, calling similarity 1.0
WPP_SF_iSD 180052c88 -> 180052a78 refcount, address, calling similarity 1.0
API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection EXTERNAL:000000b6 refcount, calling similarity 1.0
WfpPnPLookupLocalIFPropertiesHelper 180109ca0 -> 180109d40 refcount, address, calling similarity 1.0
WfpReportSysErrorAsWinError 180042798 -> 1800423f8 refcount, address, calling similarity 1.0
API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection EXTERNAL:000000b0 refcount, calling similarity 1.0
WfpErrorToWindowsError 18002e6bc refcount, calling similarity 1.0
View full diff report View RCA report Download PoC

Known Exploits

Acknowledgments