Critical RPC vulnerability in Windows

A critical vulnerability has been discovered in Windows operating systems. Find out in the article what consequences exploiting the vulnerability can have and what measures we strongly recommend you take.

CVE ID: CVE-2022-26809

CVSS Base Score: 9.8 / 10

A highly critical vulnerability with a severity score of 9.8 (out of a maximum of 10) has been discovered in Windows operating systems. Currently no exploit code is available, but this may change at any time.

The RPC vulnerability allows an attacker to compromise Windows operating systems over the Internet if their SMB (tcp/445) network port is accessible. This can lead to data manipulation or loss of control by the owner.

Our recommendation

It is to be expected that this vulnerability will be actively exploited by ransomware groups in the coming days, resulting in an increased threat. In order to close the known vulnerability, Microsoft has made an official patch available. We therefore strongly recommend updating all Windows operating systems (servers and clients) and ensuring that no SMB network ports are accessible via the Internet.

Bernhard Schildendorfer

April 14, 2022

Category

Guide

Might be also Interesting

Guide

Lywand vs. RMM – Differences & Why the Combination is Essential

RMM tools are indispensable when it comes to ensuring stable and efficient IT operations. However, when it comes to IT security, they quickly reach their limits. Find out why a vulnerability management system is the ideal addition—and how MSPs can use it to strengthen their services in the long term.

September 10, 2025

Guide

Patch management under control? The reality often shows something different.

How a security audit uncovered unexpected weaknesses in patch management - and was the start of a sustainable security strategy.

April 29, 2025

Guide

Asset Discovery Uncovers Shadow IT: A Must-Have for MSPs

In this article, you will learn how shadow IT can become an invisible but significant security risk for companies. Find out how Asset Discovery helps IT service providers to uncover hidden devices and applications on the network. We also present proven measures for controlling shadow IT and improving network security.

November 6, 2024