Vulnerability record · CVE-2022-37958 · published 13 September 2022
CVE-2022-37958: Microsoft Windows SPNEGO NEGOEX mechanism remote code execution
Microsoft · Windows 10
CVE-2022-37958 is a remote code execution flaw in the SPNEGO Extended Negotiation (NEGOEX) security mechanism on Windows. The record gives no root-cause detail beyond the mechanism name, but the flaw affects a broad set of Windows client and server versions and carries a high CVSS score. Because NEGOEX is part of Windows authentication negotiation, successful exploitation could compromise the host rather than just leak data.
Description
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.1 with network reachability, no authentication and no user interaction, plus a very high EPSS score, make this a high-priority patching target despite the high attack complexity.
What it is
CVE-2022-37958 is a remote code execution flaw in the SPNEGO Extended Negotiation (NEGOEX) security mechanism on Windows. The record gives no root-cause detail beyond the mechanism name, but the flaw affects a broad set of Windows client and server versions and carries a high CVSS score. Because NEGOEX is part of Windows authentication negotiation, successful exploitation could compromise the host rather than just leak data.
Impact
An attacker can execute arbitrary code on the target system, with high impact to confidentiality, integrity and availability per the CVSS vector. This can lead to full host compromise and potential lateral movement within a Windows environment.
Attack surface
The vector is network-reachable (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so it is reached over the network through the SPNEGO/NEGOEX negotiation path. The high attack complexity (AC:H) indicates a narrow or timing-dependent condition is required, but no authentication is needed.
Exploitation
The record shows no CISA KEV listing and no reference tags indicating a public exploit, but EPSS is very high at 0.86 (99.7th percentile), suggesting elevated likelihood of exploitation activity. Exploit availability is not confirmed by the supplied data.
What to do
- Apply the Microsoft security update for CVE-2022-37958 on all affected Windows client and server versions as the first action.
- Prioritize internet-facing and authentication-related Windows servers (domain controllers, Exchange, RDP gateways) for patching.
- Restrict network exposure of SPNEGO/NEGOEX negotiation where feasible and segment sensitive Windows systems.
- Monitor for and block anomalous NEGOEX authentication traffic at network boundaries.
- Verify patch status across the full affected product list, including older Windows 7, 8.1 and Server 2008/2012 systems.
Detection
- Monitor Windows authentication and NEGOEX-related event logs for unusual negotiation failures or malformed SPNEGO exchanges.
- Hunt for unexpected processes spawned by authentication services (lsass, svchost) on patched and unpatched hosts.
- Track network traffic to authentication endpoints for anomalous NEGOEX message patterns.
- Correlate host telemetry with EPSS-driven prioritization to focus on high-value Windows servers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-37958 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-37958), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.