Skip to content
COOEY

EXPOSURES › CVE-2022-2294

CVE-2022-2294

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-08-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-2294 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

A heap buffer overflow in WebRTC allows remote shellcode execution, enabling ransomware attackers to compromise browsers.

This vulnerability allows an attacker to execute arbitrary code remotely via WebRTC, directly impacting browsers like Chrome. DIB organizations must ensure their WebRTC implementations are patched and monitored, as this flaw was actively exploited in the wild and linked to ransomware campaigns. Failure to patch exposes systems to remote code execution, violating CMMC/NIST 800-171 requirements for patch management and vulnerability mitigation.

Shame score — A critical heap buffer overflow enabling remote code execution was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching and vulnerability management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.