CVE-2022-43552 Curl Vulnerability with Windows Server

Hori 0 Reputation points
2023-03-06T15:37:59.8933333+00:00

Hi everyone,

Nessus found a vulnerability with Curl. It looks like Windows Server 2019 uses version 7.83.1.0 which is vulnerable.

Does microsoft plan to release a patch?
Is it possible to install a new version?

Ref:

https://curl.se/docs/CVE-2022-43552.html

Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. pronichkin 26 Reputation points
    2023-04-11T22:19:08.0766667+00:00

    The issue is resolved with April, 11th round of updates for all supported operating systems. (e.g., KB5025229 for Windows Server 2019, KB5025230 for Windows Server 2022.) The inbox version of curl.exe (located at %WinDir%\System32\curl.exe) has been updated to version 8.0.1 which addresses CVE-2022-43552. Note that if some other software installed curl.exe to another location, it needs to be updated separately.

    1 person found this answer helpful.

  2. Michael Taylor 60,161 Reputation points
    2023-03-06T15:54:47.17+00:00

    There is already a discussion about this here. This forum is for Q&A not really for CVE questions. Perhaps you should go here to check the status of any CVE for Server 2019.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.