{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3omicrosoftwindows_server_2022-azure/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:arm64:*","cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:azure:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2022-34721"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","remote-code-execution","windows"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eCVE-2022-34721 is a critical remote code execution (RCE) vulnerability residing within the Windows Internet Key Exchange (IKE) extension. This vulnerability allows an unauthenticated, remote attacker to trigger arbitrary code execution on target systems by sending a specially crafted IP packet to a vulnerable host. Because the IKE protocol is frequently used in VPN implementations and network tunneling, this flaw presents a high-risk vector for remote exploitation, particularly for internet-facing systems that have the IKE service enabled. The vulnerability has been confirmed as being actively exploited in the wild, necessitating immediate patching. Defenders should focus on network-level segmentation for IKE-enabled services and ensure that all affected Windows environments are updated to mitigate the risk of unauthorized access and potential system compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary code with elevated privileges on target Windows systems. This poses a significant threat to internal network security, as attackers can leverage this access for lateral movement, data exfiltration, or the deployment of further malicious payloads. The widespread use of IKE in network infrastructure means the potential attack surface is broad, and active exploitation in the wild suggests that threat actors are actively scanning for and compromising vulnerable hosts to achieve long-term persistence within targeted networks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize the installation of security updates for CVE-2022-34721 across all internet-facing Windows servers immediately.\u003c/li\u003e\n\u003cli\u003eRestrict network access to IKE/IPsec services at the perimeter to authorized IP ranges only, reducing the available attack surface for external unauthenticated actors.\u003c/li\u003e\n\u003cli\u003eMonitor network perimeter logs for anomalous IP fragmentation or malformed packet patterns directed at UDP port 500 or 4500, which are typically used for IKE/IPsec traffic.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T05:08:41Z","date_published":"2026-08-26T05:08:41Z","id":"https://feed.craftedsignal.io/briefs/2026-08-windows-ike-rce/","summary":"CVE-2022-34721 is a critical remote code execution vulnerability in the Windows Internet Key Exchange (IKE) extension, which is being actively exploited in the wild to gain unauthorized code execution.","title":"Active Exploitation of Windows IKE Extension RCE","url":"https://feed.craftedsignal.io/briefs/2026-08-windows-ike-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:Azure:*:*:*","version":"https://jsonfeed.org/version/1.1"}