Vulnerability record · CVE-2022-23270 · published 10 May 2022
CVE-2022-23270: Windows PPTP Remote Code Execution Vulnerability
Microsoft · Windows 10
CVE-2022-23270 is a remote code execution flaw in the Windows implementation of the Point-to-Point Tunneling Protocol (PPTP). It affects a broad range of Windows client and server releases, and successful exploitation could allow an unauthenticated network attacker to run code on a vulnerable host. The record provides no root-cause detail beyond the CWE being 'insufficient information'.
Description
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.1 with network reachability, no authentication and no user interaction, combined with a very high EPSS score, makes this a high-priority patching target despite no KEV listing.
What it is
CVE-2022-23270 is a remote code execution flaw in the Windows implementation of the Point-to-Point Tunneling Protocol (PPTP). It affects a broad range of Windows client and server releases, and successful exploitation could allow an unauthenticated network attacker to run code on a vulnerable host. The record provides no root-cause detail beyond the CWE being 'insufficient information'.
Impact
An attacker who successfully exploits the flaw gains remote code execution on the target Windows system, with high impact to confidentiality, integrity and availability per the CVSS vector. This could allow full compromise of the host and any data or services it exposes.
Attack surface
The CVSS vector is AV:N/PR:N/UI:N, so the flaw is reachable over the network with no authentication and no user interaction required. The attack targets the PPTP service, meaning the host must be running and reachable on the relevant PPTP port.
Exploitation
The vulnerability is not listed in CISA KEV and no ransomware groups are documented as using it, but EPSS is very high at 0.7035 (99.35th percentile), indicating a strong likelihood of attempted exploitation. The only references are Microsoft's advisory and patch pages, with no public exploit or PoC tags.
What to do
- Apply the Microsoft security update for CVE-2022-23270 on all affected Windows client and server versions as the first action.
- If PPTP is not required, disable the PPTP service and block TCP port 1723 and GRE (IP protocol 47) at network boundaries.
- Restrict PPTP exposure to trusted networks only; do not expose PPTP endpoints directly to the internet.
- Where PPTP must remain in use, migrate to a more modern VPN protocol such as IKEv2 or WireGuard to reduce the attack surface.
- Verify patch deployment across all listed Windows versions, including legacy Windows 7, 8.1 and Server 2008/2012 systems that may be out of standard support.
Detection
- Monitor network traffic for inbound connections to TCP port 1723 and GRE protocol 47 from untrusted sources.
- Review Windows event logs and PPTP service logs for unexpected crashes, restarts or anomalous connection patterns.
- Hunt for unusual child processes or code execution originating from the PPTP service (e.g. svchost hosting RAS/PPTP) on internet-facing hosts.
- Correlate endpoint telemetry for exploitation attempts against unpatched Windows systems, particularly those still running legacy versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-23270 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-23270), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.