CVE detail
CVE-2022-34713
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
Software security platform Rezilion has expanded its Dynamic Software Bill of Materials (SBOM) capability to support Windows environments. The firm said the move will provide organizations with the tools to efficiently manage software vulnerabilities and meet new regulatory standards, addressing functionality gaps of traditional vulnerability management tools primarily designed for use with Linux OS. Features […]
newswww.csoonline.comNov 9, 2022, 11:00 AM- September 2022 Patch Tuesday forecast: No sign of cooling offHelp Net Security
September is here, and for most of us in the northern hemisphere, cooler temperatures are on the way. Unfortunately, the need to maintain and update our computer systems remains hot. August 2022 Patch Tuesday provided critical updates for all Microsoft operating systems as well as an unexpected update for Internet Explorer 11. These critical updates were driven by another zero-day vulnerability – CVE-2022-34713, found in the Microsoft Windows Support Diagnostic Tool (MSDT). There were also … More →
newswww.helpnetsecurity.comSep 9, 2022, 6:32 AM - 15th August – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 15th August, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Cisco confirms it has been breached by the Yanluowang ransomware group in late May 2022. The initial access was gained after the threat actor gained an employee’s Google account credentials, saved in […]
vendorresearch.checkpoint.comAug 15, 2022, 3:26 PM Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Black Hat USA 2022 coverage Check out our microsite for related news, photos, product releases, and more. Understanding your attack surface is key to recognizing what you are defending In this interview with Help Net Security, Marc Castejon, CEO at Silent Breach, discusses what organizations should be worried about at the moment, and what technologies they should focus in the … More →
newswww.helpnetsecurity.comAug 14, 2022, 8:00 AMrity companies to watch in 2022 Impacting Microsoft Windows Support Diagnostic Tool (MDST), the zero-day vulnerability (CVE-2022-34713) is among the most notable fixes this month and is a variant of the previously disclosed ‘Dogwalk’, Microsoft said. Rated 7.8 on the CVSSv3 severity scale, it can be exploited by tricking a target into opening a malicio
newswww.itpro.comAug 10, 2022, 11:03 AMThe US Cybersecurity and Infrastructure Security Agency (CISA) revealed on Tuesday that a recently patched vulnerability affecting the UnRAR archive extraction tool is being exploited in the wild.
newswww.securityweek.comAug 10, 2022, 10:49 AMUS Critical Infrastructure Security Agency (CISA) adds vulnerabilities in the UnRAR utility to its Known Exploited Vulnerabilities Catalog. The Cybersecurity & Infrastructure Security Agency (CISA) has added a recently disclosed security flaw, tracked as CVE-2022-30333 (CVSS score: 7.5), in the UnRAR utility to its Known Exploited Vulnerabilities Catalog. The CVE-2022-30333 flaw is a path traversal […]
newssecurityaffairs.comAug 10, 2022, 10:39 AMMicrosoft Patch Tuesday security updates for August 2022 addressed a zero-day attack remote code execution vulnerability in Windows. Microsoft Patch Tuesday security updates for August 2022 addressed 118 CVEs in multiple products, including .NET Core, Active Directory Domain Services, Azure Batch Node Agent, Azure Real Time Operating System, Azure Site Recovery, Azure Sphere, Microsoft ATA […]
newssecurityaffairs.comAug 9, 2022, 9:25 PM- Microsoft fixes exploited zero-day in Windows Support Diagnostic Tool (CVE-2022-34713)Help Net Security
The August 2022 Patch Tuesday has arrived, with fixes for an unexpectedly high number of vulnerabilities in various Microsoft products, including two zero-days: one actively exploited (CVE-2022-34713) and one not yet (CVE-2022-30134). Vulnerabilities to prioritize CVE-2022-34713 is a vulnerability in Microsoft Windows Support Diagnostic Tool (MSDT) that allows for remote code execution. For an attacker to exploit it, they must trick targets into opening a specially crafted file (delivered via email or downloaded from a … More →
newswww.helpnetsecurity.comAug 9, 2022, 8:30 PM Microsoft on Tuesday released a critical-severity bulletin to warn of a newly discovered zero-day attack exploiting a remote code execution vulnerability in its flagship Windows operating system.
newswww.securityweek.comAug 9, 2022, 6:08 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-35747CVSS 5.9 · Medium
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
1 mention - CVE-2022-35743CVSS 7.8 · High
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
- CVE-2022-22047CVSS 7.8 · High
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- CVE-2022-30190CVSS 7.8 · High
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnera…
KEV listed54 mentions - CVE-2022-26925CVSS 8.1 · High
Windows LSA Spoofing Vulnerability
- CVE-2022-26904CVSS 7.0 · High
Windows User Profile Service Elevation of Privilege Vulnerability