PT-2022-5501 · Microsoft+11 · Windows+11

Published

2022-11-08

·

Updated

2026-01-22

·

CVE-2022-38023

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows versions prior to the fixed version
Description The issue is related to errors in security settings of the Netlogon Remote Protocol (MS-NRPC) implementation in Windows operating systems. This allows a remote attacker to elevate their privileges. The vulnerability is associated with weaknesses in the RC4 protection of the NetLogon Secure channel, which uses the same algorithms as rc4-hmac cryptography in Kerberos. The secure checksum is calculated as HMAC-MD5(MD5(DATA),KEY), making it possible for an active attacker to substitute chosen data into the data stream without being detected.
Recommendations For Windows versions prior to the fixed version, update to the latest version to resolve the issue. As a temporary workaround, consider restricting access to the Netlogon RPC service until a patch is available. Avoid using the Netlogon Secure channel for sensitive data transmission until the issue is resolved.

Fix

Weakness Enumeration

Related Identifiers

ALSA-2023:0838
ALSA-2023:2127
ALT-PU-2022-3352
ALT-PU-2023-1329
ALT-PU-2023-1371
ALT-PU-2024-14683
AZL-54681
BDU:2022-06830
CESA-2023_0838
CESA-2023_1090
CVE-2022-38023
MGASA-2023-0010
OESA-2023-1048
OPENSUSE-SU-2023_0160-1
OPENSUSE-SU-2023_0163-1
OPENSUSE-SU-2023_0222-1
OPENSUSE-SU-2024:12587-1
RHSA-2023:0637
RHSA-2023:0638
RHSA-2023:0639
RHSA-2023:0838
RHSA-2023:1090
RHSA-2023:2127
RHSA-2023:2136
RHSA-2023:2137
RHSA-2023:3491
RHSA-2023_0838
RHSA-2023_1090
RHSA-2023_2127
RLSA-2023:0838
RLSA-2023:2127
SUSE-SU-2023:0014-1
SUSE-SU-2023:0081-1
SUSE-SU-2023:0122-1
SUSE-SU-2023:0126-1
SUSE-SU-2023:0160-1
SUSE-SU-2023:0162-1
SUSE-SU-2023:0163-1
SUSE-SU-2023:0164-1
SUSE-SU-2023:0222-1
SUSE-SU-2023:0620-1
USN-5822-1
USN-5822-2
USN-5936-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Rocky Linux
Samba
Suse
Ubuntu
Windows