by @j00sean
01 Mar 2023

CVE-2022-44666: Microsoft Windows Contacts (VCF/Contact/LDAP) syslink control href attribute escape vulnerability

by @j00sean
01 Mar 2023

CVE-2022-44666: Microsoft Windows Contacts (VCF/Contact/LDAP) syslink control href attribute escape vulnerability

CVEs

7.8 High Severity

OS

Windows 8.1
Windows 8.1Microsoft
6.3.9600.20520.*
6.3.9600.20520.*
RT.*
*.*
*.*
*.*
*.*
-.*
-.*
-.*
Windows 10
Windows 10Microsoft
1003.*
1004.*
2601.*
2478.*
2479.*
2025.*
21H22.*
24H2.*
2024.*
23H2.*
WR8
6.3.9600.20520.*
*.*
*.*
*.*
-.*
-.*
-.*
7375.*
6.2.9200.25073.*
6.2.9200.24975.*
6.2.9200.25031.*
6.2.9200.24919.*
6.2.9200.24768.*
6.2.9200.24116.*
4113.*
7378.*
R2.*
10.0.14393.7876.*
10.0.14393.7606.*
10.0.14393.7428.*
10.0.14393.6897.*
10.0.14393.5582.*
10.0.14393.6981.*
10.0.14393.6796.*
10.0.14393.7070.*
10.0.14393.7515.*
10.0.14393.7336.*
10.0.17763.7009.*
18410.*
10.0.17763.6414.*
10.0.17763.6659.*
10.0.17763.5458.*
10.0.17763.3770.*
10.0.17763.5936.*
10.0.17763.5820.*
10.0.17763.6532.*
10.0.17763.5696.*

Screenshots from the blog posts

blog-posts/images/cleqaxy4h0z070kqw3r7w3mx3.jpgblog-posts/images/cleqaxy4h0z070kqw3r7w3mx3.jpg

Summary

My thoughts and more on this bug!

Description

users/photos/clemvjnl46kz30juk5c0ta59k.jpg

@j00sean

3 posts

Finding bugs everywhere

Total vcoins

3.2K

Comments (0)