EXPOSURES › CVE-2022-2294
CVE-2022-2294
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA heap buffer overflow in WebRTC allows remote shellcode execution, enabling ransomware attackers to compromise browsers.
This vulnerability allows an attacker to execute arbitrary code remotely via WebRTC, directly impacting browsers like Chrome. DIB organizations must ensure their WebRTC implementations are patched and monitored, as this flaw was actively exploited in the wild and linked to ransomware campaigns. Failure to patch exposes systems to remote code execution, violating CMMC/NIST 800-171 requirements for patch management and vulnerability mitigation.
Shame score — A critical heap buffer overflow enabling remote code execution was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching and vulnerability management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.