PT-2022-3863 · Microsoft · Windows Server+1

Ben Barnea

·

Published

2022-07-12

·

Updated

2023-05-17

·

CVE-2022-30216

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Server versions prior to the fixed version
Description The issue is related to a tampering vulnerability in the Windows Server service, allowing attackers to affect the system. This vulnerability can lead to authentication coercion, enabling attackers to perform server spoofing or trigger authentication coercion on the victim. The Server service, responsible for managing SMB shares, is impacted, and the vulnerability is significant because the service runs by default on every Windows machine.
Recommendations For Windows Server versions prior to the fixed version, consider disabling the srvsvc service until a patch is available. Restrict access to the pipesrvsvc named pipe to minimize the risk of exploitation. Avoid using the Server service for creating, configuring, querying, or deleting shares through RPC over a named pipe until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2022-04666
CVE-2022-30216

Affected Products

Windows
Windows Server