by @j00sean
01 Mar 2023

CVE-2022-44666: Microsoft Windows Contacts (VCF/Contact/LDAP) syslink control href attribute escape vulnerability

by @j00sean
01 Mar 2023

CVE-2022-44666: Microsoft Windows Contacts (VCF/Contact/LDAP) syslink control href attribute escape vulnerability

CVEs

7.8 High Severity

OS

Windows 8.1
Windows 8.1Microsoft
6.3.9600.20520.*
6.3.9600.20520.*
RT.*
*.*
*.*
*.*
*.*
-.*
-.*
-.*
Windows 10
Windows 10Microsoft
30H2.*
25H2.*
AMD6.*
8662.*
1002.*
ARM6.*
1003.*
1004.*
2601.*
2478.*
WR8
6.3.9600.20520.*
*.*
*.*
*.*
-.*
-.*
-.*
6.2.9200.25973.*
4117.*
7382.*
NT 6.2.*
7375.*
6.2.9200.25073.*
6.2.9200.24975.*
6.2.9200.25031.*
6.2.9200.24919.*
6.2.9200.24768.*
10.0.14393.9140.*
10.0.14393.9062.*
10.0.14393.9060.*
10.0.14393.8957.*
10.0.14393.8868.*
10.0.14393.8688.*
10.0.14393.8783.*
10.0.14393.8594.*
10.0.14393.8524.*
10.0.14393.8519.*
10.0.17763.3772.*
10.0.17763.5579.*
10.0.17763.8389.*
10.0.17763.8755.*
10.0.17763.7683.*
10.0.17763.7240.*
10.0.17763.8281.*
10.0.17763.8647.*
10.0.17763.7249.*
10.0.17763.7322.*

Screenshots from the blog posts

blog-posts/images/cleqaxy4h0z070kqw3r7w3mx3.jpgblog-posts/images/cleqaxy4h0z070kqw3r7w3mx3.jpg

Summary

My thoughts and more on this bug!

Description

users/photos/clemvjnl46kz30juk5c0ta59k.jpg

@j00sean

3 posts

Finding bugs everywhere

Total vcoins

0

Comments (0)