logo

CVE-2022-37958

ID: c78a021b-f39e-5724-958a-62246401161c

STIX ID: report--c78a021b-f39e-5724-958a-62246401161c

Feed Name: Arctic Wolf Blog

Threat Score
70/100

Date Published: 2022-12-14

Date Updated: 2026-04-27

...
...

Microsoft reclassified CVE-2022-37958 (SPNEGO NEGOEX) as Critical after researchers determined it could allow pre-auth remote code execution and may be wormable; the vulnerability affects Windows 7 and newer across multiple protocols (SMB, RDP, HTTP, etc.). No active exploitation or public PoC had been observed at the time of the report, but due to wormable potential Artic Wolf warns threat actors will likely pursue exploit development; recommended mitigations are to apply Microsoft’s security updates and limit exposure of services like RDP/SMB to the internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.