Rewterz
Rewterz Threat Advisory – Multiple Citrix ADC and Citrix Gateway Vulnerabilities
May 26, 2022
Rewterz
Rewterz Threat Alert – Microsoft Issues A Warning Against New Evasive Web Skimming Campaign – Active IOCs
May 26, 2022

Rewterz Threat Advisory – CVE-2022-29246 – Microsoft Azure RTOS USBX Vulnerability

Severity

High

Analysis Summary

CVE-2022-29246

Azure RTOS USBX is vulnerable to a buffer overflow, caused by improper bounds checking by the function DFU upload. By sending a specially-crafted request, a remote attacker could overflow a buffer and execute arbitrary code on the system.

Impact

  • Buffer Overflow

Indicators Of Compromise

CVE

  • CVE-2022-29246

Affected Vendors

  • Microsoft

Affected Products

  • Azure RTOS USBX 6.1.10

Remediation

Refer to Microsoft Security Advisory for patch, upgrade or suggested workaround information.

Microsoft Security Advisory