ZeroHour

CVE-2022-34713

KEVmass

Remote Code Execution in Microsoft Windows Support Diagnostic Tool (MSDT) (DogWalk)

CISA: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
68%p99
Published
()
KEV added
AI analysis

CVE-2022-34713, commonly referred to as 'DogWalk,' is a remote code execution vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT), patched in Microsoft's August 2022 Patch Tuesday release. The flaw requires user interaction: a user who engages with attacker-supplied content that invokes MSDT can allow the attacker's file operations to run in the context of the logged-on user, yielding high-impact code execution (confidentiality, integrity, and availability all rated high in the CVSS vector). Affected products span essentially the entire supported Windows installed base at the time: Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H2), Windows 11 21H2, and Windows Server 2008 and 2012. The vulnerability was confirmed by Microsoft as an actively exploited zero-day in August 2022 and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-08-09, with a required action to apply vendor updates. EPSS assigns it a 67.8% probability of exploitation within 30 days (99th percentile), consistent with in-the-wild use.

What to do: Apply the August 2022 (or later) Windows security updates on all affected Windows 7, 8.1, RT 8.1, 10 (1507–21H2), 11 21H2, Server 2008, and Server 2012 systems per vendor instructions, prioritizing user-facing workstations where exploitation depends on user interaction. Given the KEV listing, federal and high-value environments should verify patch status immediately and hunt for suspicious MSDT/diagnostic-tool invocations. No public PoC is known, but treat any unpatched system as exposed given confirmed in-the-wild exploitation.

Affected
microsoft Windows 101507, 1607, 1809, 20H2, 21H1, 21H2
microsoft Windows 1121H2
microsoft Windows 7all supported editions as listed (no SP range specified in source data)
microsoft Windows 8.1all supported editions as listed
microsoft Windows RT 8.1as listed
microsoft Windows Server 2008all supported editions as listed
microsoft Windows Server 2012all supported editions as listed
Estimated exposure
masshundreds of millions of devices — plausibly 500M to 1B+ endpoints and servers, since nearly every supported Windows release at disclosure is affected — The affected-version list spans the entire mainstream Windows installed base at the time (Windows 7 through Windows 11 21H2 plus Server 2008/2012), which represented roughly a billion or more active Windows devices, so exposure is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news