CVE-2022-32230: Windows SMB Denial of Service Vulnerability

Overview

Severity
N/A
Category
Denial of Service
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2022-Jun
Released
2022-06-14
EPSS Score
28.75% (percentile: 96.5%)

FAQ

Why is this Rapid7 CVE included in the Security Update Guide? The vulnerability assigned to this CVE was originally classified as a stability bug in Windows. Rapid7 discovered that this bug could be used to cause a denial of service condition on affected versions of Windows. Microsoft had provided an update to address this issue prior to being contacted about it by Rapid 7. Microsoft appreciates the strong partnership that we have with Rapid7. Why are the May updates associated with the operating systems rows in the Security Updates table? This vulnerability was addressed in the May 2022 security updates.

Affected Products (15)

Windows

  • Windows 10 Version 1809 for 32-bit Systems
  • Windows 10 Version 1809 for x64-based Systems
  • Windows 10 Version 1809 for ARM64-based Systems
  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)
  • Windows 10 Version 21H1 for x64-based Systems
  • Windows 10 Version 21H1 for ARM64-based Systems
  • Windows 10 Version 21H1 for 32-bit Systems
  • Windows 10 Version 20H2 for 32-bit Systems
  • Windows 10 Version 20H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems

Security Updates (4)

Acknowledgments

<a href="https://twitter.com/zerosteiner">Spencer McIntyre</a> with <a href="https://www.rapid7.com/">Rapid7</a>

Revision History

  • 2022-06-14: Information published.