RPC Remote Code Execution (CVE-2022-22038)

Опубликовано: 13 Июнь 2026
на канале: Alexander Leonov
326
0

Remote Code Execution in Remote Procedure Call Runtime (CVE-2022-22038). Here Microsoft has a POC exploit. This July Patch Tuesday bug could allow a remote, unauthenticated attacker to exploit code on an affected system. While not specified in the bulletin, the presumption is that the code execution would occur at elevated privileges. Combine these attributes and you end up with a potentially wormable bug. Microsoft states the attack complexity is high. Additional actions by an attacker are required in order to prepare a target for successful exploitation and an attacker would need to make “repeated exploitation attempts” to take advantage of this bug, but unless you are actively blocking RPC activity, you may not see these attempts.

Blogpost: https://avleonov.com/2022/07/23/micro...
Full report: https://avleonov.com/vulristics_repor...

#RPC #microsoft #patchtuesday