CVE-2022-34713Patch(microsoft / windows_10_1507)

LOWCVSS 7.8 · HIGHCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

1.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-08-30. Apply updates per vendor instructions.

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_20h2

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_20h2windows_10_21h1windows_10_21h2windows_11_21h2windows_7windows_8.1windows_rt_8.1

2 versions affected across 16 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-10: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-10: 104-10
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Vicarius@vicariusltd
    Patch

    Well that's one way to spearphish 😅 _____ CVE of the Week: DogWalk RCE in Windows MSDT (CVE-2022-34713) We know that legacy systems remain the quiet backbone of many organizations. That’s why we’ve focused our recent efforts on ensuring even your legacy environments are shielded against classic exploits like this critical path traversal flaw in the Windows Support Diagnostic Tool (MSDT) that allows attackers to bypass "Mark of the Web" protections and plant malicious files directly into a system's startup directory. Why it matters: - Attackers gain a permanent foothold with the user's privileges. - Exploited via crafted .diagcab files that often slip past basic email filters. Recommended actions: 1. Ensure the August 2022 (or later) cumulative updates are applied to all Windows and Server 2008/2012/2016/2019 instances. 2. For systems that cannot be patched, unregister the ms-msdt URL protocol handler to break the link between the browser and the vulnerable diagnostic tool. Use this mitigation script to apply the non-patch workaround: https://www.vicarius.io/vsociety/posts/cve-2022-34713-mitigation-script-dogwalk-path-traversal-vulnerability-in-the-windows-support-diagnostic-tool ^ This script serves as a critical stop-gap measure to harden your environment against CVE-2022-34713 when immediate patching is not feasible.

    Post summary

    The post explains CVE‑2022‑34713, a path‑traversal RCE in Windows MSDT, and urges admins to install August 2022 updates or use a provided mitigation script.

    01060341
    2.0K followersView on X
CPE platform detail19 entries

19 of 19 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507---
OSmicrosoftwindows_10_1607---
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_20h2---
OSmicrosoftwindows_10_21h1--arm64
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_7--x64
OSmicrosoftwindows_7--x86
OSmicrosoftwindows_8.1--x64
OSmicrosoftwindows_8.1--x86
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_20h2---

Explore more