CVE-2022-37958
vulnerability analysis and mitigation

Overview

CVE-2022-37958 is a critical remote code execution (RCE) vulnerability in the SPNEGO Extended Negotiation (NEGOEX) Security Mechanism affecting Windows operating systems. Initially disclosed and patched in September 2022 as an information disclosure vulnerability, it was later reclassified as Critical in December 2022 after security researcher Valentina Palmiotti from IBM Security's X-Force Red team discovered its RCE capabilities (Tenable Blog).

Technical details

The vulnerability exists in the SPNEGO NEGOEX protocol, which is an internet standard for negotiating GSSAPI technology used for authentication between client and server. Multiple critical protocols including Server Message Block (SMB), Remote Desktop Protocol (RDP), Simple Mail Transfer Protocol (SMTP), and HTTP use or can be configured to use NEGOEX for authentication by default. The vulnerability was initially assigned a CVSSv3 score of 7.5 but was later upgraded to 8.1 after reclassification as an RCE vulnerability (Arctic Wolf, Tenable Blog).

Impact

The vulnerability could allow an attacker to execute arbitrary code remotely by accessing the NEGOEX protocol via any Windows application protocol that authenticates. Security researchers have indicated that the vulnerability has the potential to be wormable, making it potentially more severe than EternalBlue (CVE-2017-0144) due to its impact on multiple protocols rather than just SMBv1 (Tenable Blog).

Mitigation and workarounds

Microsoft released security updates to address CVE-2022-37958 as part of their September 2022 Patch Tuesday release. Organizations that applied the September 2022 updates are protected against this vulnerability, as the December 2022 update only included informational changes to the classification. It is strongly recommended to review and apply all applicable security updates to impacted Windows products (Arctic Wolf).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management