by @j00sean
01 Mar 2023
#cve_analysis
CVE-2022-44666: Microsoft Windows Contacts (VCF/Contact/LDAP) syslink control href attribute escape vulnerability
by @j00sean
01 Mar 2023
CVE-2022-44666: Microsoft Windows Contacts (VCF/Contact/LDAP) syslink control href attribute escape vulnerability
OS
Windows 8.1Microsoft
6.3.9600.20520.*
6.3.9600.20520.*
RT.*
*.*
*.*
*.*
*.*
-.*
-.*
-.*
show all related OS
Windows 10Microsoft
30H2.*
25H2.*
AMD6.*
8662.*
1002.*
ARM6.*
1003.*
1004.*
2601.*
2478.*
WR8
Windows RT 8.1Microsoft
6.3.9600.20520.*
*.*
*.*
*.*
-.*
-.*
-.*
Windows Server 2012Microsoft
7382.*
7375.*
6.2.9200.25073.*
6.2.9200.24975.*
6.2.9200.25031.*
6.2.9200.24919.*
6.2.9200.24768.*
6.2.9200.24116.*
4113.*
Null.*
Windows Server 2016Microsoft
10.0.14393.8594.*
10.0.14393.8524.*
10.0.14393.8519.*
10.0.14393.8519.*
10.0.14393.8422.*
10.0.14393.8416.*
10.0.14393.8330.*
10.0.14393.8246.*
10.0.14393.8066.*
10.0.14393.8148.*
Windows Server 2019Microsoft
10.0.17763.8027.*
10.0.17763.7922.*
10.0.17763.7919.*
10.0.17763.7792.*
10.0.17763.7783.*
10.0.17763.7678.*
10.0.17763.7558.*
10.0.17763.7136.*
10.0.17763.7434.*
10.0.17763.7314.*
Screenshots from the blog posts
Summary
My thoughts and more on this bug!
Description
Comments (0)