Cybersecurity Network Management IT and Network Support

Cybersecurity Threat Advisory: Microsoft Critical Remote Code Execution Vulnerability

Jason Franks April 14, 2022 1 min read

Advisory Overview

The Cybersecurity and Infrastructure Security Agency (CISA), a unit of the Department of Homeland Security (DHS), has issued an alert regarding an advisory released by Microsoft concerning a critical remote code execution vulnerability.

What Is the Threat?

The vulnerability, which is identified as CVE-2022-26809, affects the Remote Procedure Runtime Library. According to Microsoft, the vulnerability enables a cyberattacker to take control of a system. This would be done by “sending a specially crafted RPC call (remote procedure call) to an RPC host. This could result in remote code execution on the server side with the same permissions as the RPC service.”

What Are the Recommendations?

Microsoft recommends the following actions:

  • Block TCP port 445 at the enterprise perimeter firewall
  • Follow Microsoft guidelines to secure Server Message Block (SMB) traffic

Further, CISA recommends that users and administrators review Microsoft’s advisory and apply the recommended mitigations.


As part of our effort to inform our clients about potential and serious cybersecurity issues, MCP provides advisories about vulnerabilities and exploits that could threaten the operations of their critical communications networks. Sign up to receive these advisories in your inbox as soon as they are released.

Don't forget to share this post!

Jason Franks

Related posts

Cybersecurity Network Management IT and Network Support

Cybersecurity Threat Advisory: Microsoft’s Patch Critical RCE Flaws

September 18, 2020
Mike Beagles
Cybersecurity Network Management IT and Network Support

Cybersecurity Threat Advisory: Disguised Windows Files and Documentation

September 20, 2021
Mike Beagles
Cybersecurity IT and Network Support

Cyber Tip of the Week: EDR, XDR, and MDR

June 15, 2022
Jason Franks