Executive brief
A remote code execution vulnerability exists in Microsoft Windows Scripting Languages (specifically JScript9) due to an out-of-bounds write flaw. An attacker can exploit this by enticing a user to visit a specially crafted website or open a malicious file, leading to arbitrary code execution.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.10240.19567
- Microsoft Windows 11 21H2, 22H2
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016 up to (excluding) 10.0.14393.5501
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.3650
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.1249
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
Timeline
- 2022-11-08: disclosed
- 2022-11-08: patched
- 2022-11-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-11-08: exploited: Reported as exploited in the wild at time of publication.