Vulnerability record · CVE-2022-21972 · published 10 May 2022
CVE-2022-21972: Windows PPTP Remote Code Execution Vulnerability
Microsoft · Windows 10
CVE-2022-21972 is a remote code execution flaw in the Windows Point-to-Point Tunneling Protocol (PPTP). Microsoft rates it high severity (CVSS 3.1 8.1), and because PPTP is a network-facing service, an unauthenticated attacker on the network can reach the vulnerable code. The record gives no root-cause detail beyond the CWE being 'insufficient information', so the exact defect is not described.
Description
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.1 with network reachability, no authentication and no user interaction, plus a very high EPSS score, make this a serious exposure despite the absence of KEV listing.
What it is
CVE-2022-21972 is a remote code execution flaw in the Windows Point-to-Point Tunneling Protocol (PPTP). Microsoft rates it high severity (CVSS 3.1 8.1), and because PPTP is a network-facing service, an unauthenticated attacker on the network can reach the vulnerable code. The record gives no root-cause detail beyond the CWE being 'insufficient information', so the exact defect is not described.
Impact
Successful exploitation gives the attacker code execution in the context of the affected Windows component, with high confidentiality, integrity and availability impact per the CVSS vector. That means full compromise of the target host rather than just a denial of service.
Attack surface
The vector is AV:N/PR:N/UI:N, so the flaw is reachable over the network with no authentication and no user interaction. The attack targets the PPTP service on Windows hosts, so any system with PPTP reachable from an untrusted network is exposed.
Exploitation
CISA KEV does not list this CVE, and no reference is tagged as exploit code, so there is no confirmed in-the-wild exploitation in this record. EPSS is very high (0.79347, 99.58th percentile), indicating strong predicted likelihood of exploitation activity.
What to do
- Apply the Microsoft security update for CVE-2022-21972 on all affected Windows versions as the first action.
- Disable or block PPTP where it is not required; PPTP is deprecated and can be replaced with a modern VPN protocol.
- Restrict inbound TCP 1723 and GRE (IP protocol 47) to trusted networks only, since PPTP uses these to establish tunnels.
- Monitor Microsoft advisories for updated guidance and re-check exposure after patching.
Detection
- Alert on inbound connections to TCP 1723 and GRE protocol 47 from untrusted or external networks.
- Monitor Windows event logs and crash dumps for faults in the PPTP/RAS components on exposed hosts.
- Track unexpected process creation or network activity originating from the PPTP service on servers and workstations.
- Inventory hosts with PPTP enabled or listening to confirm which systems still need the patch.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-21972 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-21972), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.