CVE-2022-32230 - CVE House
Back to Database
Status published High CVE-2022-32230

SMBv3 FileNormalizedNameInformation NULL Pointer Dereference

Vulnerability Description

Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the April, 2022 patch set. By sending a malformed FileNormalizedNameInformation SMBv3 request over a named pipe, an attacker can cause a Blue Screen of Death (BSOD) crash of the Windows kernel. For most systems, this attack requires authentication, except in the special case of Windows Domain Controllers, where unauthenticated users can always open named pipes as long as they can establish an SMB session. Typically, after the BSOD, the victim SMBv3 server will reboot.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-32230

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Spencer McIntyre of Rapid7

Affected Vendor

Affected Software

Windows 10 Version 20H2, Windows Server Version 20H2, Windows 10 Version 21H1, Windows 10 Version 21H2
Vulnerable Versions:
19042.1706, 19043.1706, 19044.1706

Timeline

Official Publish: June 14th, 2022
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)