← Vulnerability feed

Vulnerability record · CVE-2022-23270 · published 10 May 2022

CVE-2022-23270: Windows PPTP Remote Code Execution Vulnerability

Microsoft · Windows 10

CVE-2022-23270 is a remote code execution flaw in the Windows implementation of the Point-to-Point Tunneling Protocol (PPTP). It affects a broad range of Windows client and server releases, and successful exploitation could allow an unauthenticated network attacker to run code on a vulnerable host. The record provides no root-cause detail beyond the CWE being 'insufficient information'.

8.1 CVSS 3.1 High EPSS 70% · top 0.6%
8.1CVSS 3.1 base score, v2 9.3
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.1 with network reachability, no authentication and no user interaction, combined with a very high EPSS score, makes this a high-priority patching target despite no KEV listing.

What it is

CVE-2022-23270 is a remote code execution flaw in the Windows implementation of the Point-to-Point Tunneling Protocol (PPTP). It affects a broad range of Windows client and server releases, and successful exploitation could allow an unauthenticated network attacker to run code on a vulnerable host. The record provides no root-cause detail beyond the CWE being 'insufficient information'.

Impact

An attacker who successfully exploits the flaw gains remote code execution on the target Windows system, with high impact to confidentiality, integrity and availability per the CVSS vector. This could allow full compromise of the host and any data or services it exposes.

Attack surface

The CVSS vector is AV:N/PR:N/UI:N, so the flaw is reachable over the network with no authentication and no user interaction required. The attack targets the PPTP service, meaning the host must be running and reachable on the relevant PPTP port.

Exploitation

The vulnerability is not listed in CISA KEV and no ransomware groups are documented as using it, but EPSS is very high at 0.7035 (99.35th percentile), indicating a strong likelihood of attempted exploitation. The only references are Microsoft's advisory and patch pages, with no public exploit or PoC tags.

What to do

  • Apply the Microsoft security update for CVE-2022-23270 on all affected Windows client and server versions as the first action.
  • If PPTP is not required, disable the PPTP service and block TCP port 1723 and GRE (IP protocol 47) at network boundaries.
  • Restrict PPTP exposure to trusted networks only; do not expose PPTP endpoints directly to the internet.
  • Where PPTP must remain in use, migrate to a more modern VPN protocol such as IKEv2 or WireGuard to reduce the attack surface.
  • Verify patch deployment across all listed Windows versions, including legacy Windows 7, 8.1 and Server 2008/2012 systems that may be out of standard support.

Detection

  • Monitor network traffic for inbound connections to TCP port 1723 and GRE protocol 47 from untrusted sources.
  • Review Windows event logs and PPTP service logs for unexpected crashes, restarts or anomalous connection patterns.
  • Hunt for unusual child processes or code execution originating from the PPTP service (e.g. svchost hosting RAS/PPTP) on internet-facing hosts.
  • Correlate endpoint telemetry for exploitation attempts against unpatched Windows systems, particularly those still running legacy versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-23270 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-0708Microsoft Remote Desktop Services use-after-free remote code executionRemote Desktop Services (formerly Terminal Services) contains a use-after-free flaw that lets an unauthenticated attacker execute code by sending spe…KEVEPSS 100%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed8.8CVE-2022-41128Windows Scripting Languages out-of-bounds write allows remote code executionCVE-2022-41128 is an out-of-bounds write (CWE-787) in Windows Scripting Languages that leads to remote code execution. Microsoft rates it 8.8 HIGH wi…KEVEPSS 25%analysed8.8CVE-2022-26923Microsoft Active Directory Domain Services certificate validation privilege escalationActive Directory Domain Services fails to properly validate certificate attributes, allowing a low-privileged domain user to obtain a certificate tha…KEVEPSS 84%analysed8.8CVE-2021-40444Microsoft MSHTML remote code execution via malicious Office documentCVE-2021-40444 is a remote code execution flaw in the MSHTML browser rendering engine on Microsoft Windows. An attacker can embed a malicious ActiveX…KEVEPSS 97%analysed8.8CVE-2020-1020Windows Adobe Type Manager Library font parsing out-of-bounds write RCEMicrosoft Windows Adobe Type Manager Library mishandles a specially crafted multi-master font in Adobe Type 1 PostScript format, causing an out-of-bo…KEVEPSS 65%analysed8.8CVE-2019-0903Windows GDI memory handling remote code executionWindows Graphics Device Interface (GDI) mishandles objects in memory, allowing remote code execution. The record gives no root-cause detail beyond th…KEVEPSS 22%analysed

Source: NIST National Vulnerability Database (record CVE-2022-23270), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.