Windows Server Update Service, Deserialization of Untrusted Data, CVE-2022-21971 (Critical)

Listen to this Post

This vulnerability exists within the Windows Server Update Service (WSUS) where the software insecurely deserializes user-supplied data without proper validation. Deserialization is the process of converting serialized data from a file or network stream back into an object. An attacker can exploit this by sending a specially crafted malicious serialized object to the WSUS server. When the server deserializes this untrusted data, it triggers the execution of arbitrary code within the context of the WSUS application, potentially granting the attacker full control over the system. As the service typically runs with high privileges, successful exploitation can lead to complete compromise of the WSUS server, allowing an attacker to deploy malware, steal sensitive update information, or use the server as a pivot point into the internal network. The attack can be performed remotely without authentication, making it highly severe.
Platform: Windows Server
Version: WSUS
Vulnerability: Deserialization RCE
Severity: Critical

date: 2022-01-11

Prediction: 2022-02-08

What Undercode Say:

`ysoserial.exe -f BinaryFormatter -g TypeConfuseDelegate -c “cmd /c calc.exe” > payload.bin`
`curl -X POST –data-binary @payload.bin http://target-wsus/api/endpoint`
Code analysis of the vulnerable component would show a direct call to `BinaryFormatter.Deserialize()` with unsanitized network input.

How Exploit:

Craft malicious serialized object.

Send object to WSUS API.

Trigger deserialization for RCE.

Protection from this CVE

Install Microsoft patch.

Block unnecessary ports.

Use application firewalls.

Impact:

Remote Code Execution

Network Compromise

Update Infrastructure Attack

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: www.cve.org
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top