PT-2022-1689 · Microsoft · Windows Internet Key Exchange (Ike) Protocol Extensions+1

Polar Bear

·

Published

2022-01-11

·

Updated

2024-11-14

·

CVE-2022-21849

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Internet Key Exchange (IKE) Protocol Extensions (affected versions not specified)
Description The issue is related to the incorrect management of code generation in the Windows IKE protocol extension, which can be exploited by a remote attacker to execute arbitrary code. This allows the attacker to potentially affect the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2022-00940
CVE-2022-21849

Affected Products

Windows
Windows Internet Key Exchange (Ike) Protocol Extensions