CVE-2022-26926 — Windows Address Book Remote Code Execution Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5013963 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 for x64-based Systems | 5013963 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5013952 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5013952 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5013941 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for ARM64-based Systems | 5013941 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5013941 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1909 for 32-bit Systems | 5013945 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1909 for ARM64-based Systems | 5013945 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1909 for x64-based Systems | 5013945 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 20H2 for 32-bit Systems | 5013942 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 20H2 for ARM64-based Systems | 5013942 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H1 for 32-bit Systems | 5013942 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H1 for ARM64-based Systems | 5013942 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H1 for x64-based Systems | 5013942 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5013942 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5013942 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5013942 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 version 21H2 for ARM64-based Systems | 5013943 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 version 21H2 for x64-based Systems | 5013943 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 7 for 32-bit Systems Service Pack 1 5014012 (Monthly Rollup) 5013999 (Security Only) Important Remote Code Execution 5012626 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.25954 Yes 5014012 5013999 Windows 7 for x64-based Systems Service Pack 1 5014012 (Monthly Rollup) 5013999 (Security Only) Important Remote Code Execution 5012626 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.25954 Yes 5014012 5013999 Windows 8.1 for 32-bit systems 5014011 (Monthly Rollup) 5014001 (Security Only) Important Remote Code Execution 5012670 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20371 6.3.9600.20365 Yes 5014011 5014001 Windows 8.1 for x64-based systems 5014011 (Monthly Rollup) 5014001 (Security Only) Important Remote Code Execution 5012670 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20371 6.3.9600.20365 Yes 5014011 5014001 Windows RT 8.1 | 5014025 (ServicingStackUpdate) |
Important | Remote Code Execution | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 5014010 (Monthly Rollup) 5014006 (Security Only) Important Remote Code Execution 5012658 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21481 Yes 5014010 5014006 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5014010 (Monthly Rollup) 5014006 (Security Only) Important Remote Code Execution 5012658 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21481 Yes 5014010 5014006 Windows Server 2008 for x64-based Systems Service Pack 2 5014010 (Monthly Rollup) 5014006 (Security Only) Important Remote Code Execution 5012658 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21481 Yes 5014010 5014006 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5014010 (Monthly Rollup) 5014006 (Security Only) Important Remote Code Execution 5012658 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21481 Yes 5014010 5014006 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5014012 (Monthly Rollup) 5013999 (Security Only) Important Remote Code Execution 5012626 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.25954 Yes 5014012 5013999 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5014012 (Monthly Rollup) 5013999 (Security Only) Important Remote Code Execution 5012626 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.25954 Yes 5014012 5013999 Windows Server 2012 5014017 (Monthly Rollup) 5014018 (Security Only) Important Remote Code Execution 5012650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.2.9200.23714 Yes 5014017 5014018 Windows Server 2012 (Server Core installation) 5014017 (Monthly Rollup) 5014018 (Security Only) Important Remote Code Execution 5012650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.2.9200.23714 Yes 5014017 5014018 Windows Server 2012 R2 5014011 (Monthly Rollup) 5014001 (Security Only) Important Remote Code Execution 5012670 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20371 6.3.9600.20365 Yes 5014011 5014001 Windows Server 2012 R2 (Server Core installation) 5014011 (Monthly Rollup) 5014001 (Security Only) Important Remote Code Execution 5012670 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20371 6.3.9600.20365 Yes 5014011 5014001 Windows Server 2016 | 5013952 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2016 (Server Core installation) | 5013952 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2019 | 5013941 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2019 (Server Core installation) | 5013941 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2022 | 5013944 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2022 (Server Core installation) | 5013944 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server, version 20H2 (Server Core Installation) | 5013942 (Security Update) |
Important | Remote Code Execution | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5013963 |
Security Update | Yes |
5013952 |
Security Update | Yes |
5013941 |
Security Update | Yes |
5013945 |
Security Update | Yes |
5013942 |
Security Update | Yes |
5013943 |
Security Update | Yes |
5014025 |
ServicingStackUpdate | Yes |
5013944 |
Security Update | Yes |
Patch Diff
Integer-overflow heap corruption in the Windows Address Book (wab32.dll) property merge path. ScMergePropValues calls _ScCountPropsEx twice to size two property arrays (local_1c and local_20), then allocates with MAPIAllocateBuffer(local_20 + local_1c, ...) - an UNCHECKED 32-bit addition of two attacker-influenced sizes. A crafted .wab/.vcf/contact file whose two property arrays sum past 4GB wraps the total to a small value, MAPIAllocateBuffer returns an undersized buffer, and the subsequent property copy overflows the heap. The May 2022 patch routes the size addition through ULongAdd (checked add, fails on overflow) and hardens _ScCountPropsEx (gains a 4th parameter and restructured NULL/bounds handling). 32-bit binary; reached by opening or previewing a malicious address-book file. Verified by ghidriff of 10.0.19041.1110 -> .1706.
| Function | Address | Change | Note |
|---|---|---|---|
ScMergePropValues |
|
code (size addition routed through ULongAdd) | PRE: local_14 = MAPIAllocateBuffer(local_20 + local_1c, &local_c) - unchecked 32-bit add of the two counted property sizes. POST: the add is replaced by ULongAdd(local_1c, local_20, &size) with the overflow branch bailing before allocation. |
_ScCountPropsEx@16 |
|
code (signature + bounds handling hardened) | Gains a 4th parameter (param_4 output) and restructures the NULL/param checks and the counting loop (uVar8 = *param_2 >> 0x10 ...). Produces the per-array size consumed by ScMergePropValues. |
ULongAdd |
|
newly called | Checked-addition helper; byte-identical itself, newly invoked from ScMergePropValues to guard the allocation size. |
Attack Path
Two attacker-controlled property-array sizes are summed without overflow check, producing an undersized allocation the merge then overflows
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.