The issue is resolved with April, 11th round of updates for all supported operating systems. (e.g., KB5025229 for Windows Server 2019, KB5025230 for Windows Server 2022.)
The inbox version of curl.exe
(located at %WinDir%\System32\curl.exe
) has been updated to version 8.0.1
which addresses CVE-2022-43552. Note that if some other software installed curl.exe
to another location, it needs to be updated separately.
CVE-2022-43552 Curl Vulnerability with Windows Server
Hori
0
Reputation points
Hi everyone,
Nessus found a vulnerability with Curl. It looks like Windows Server 2019 uses version 7.83.1.0 which is vulnerable.
Does microsoft plan to release a patch?
Is it possible to install a new version?
Ref:
Windows for business | Windows Server | User experience | Other
20,212 questions
Windows for business | Windows Server | Devices and deployment | Configure application groups
2 answers
Sort by: Most helpful
-
pronichkin 26 Reputation points
2023-04-11T22:19:08.0766667+00:00 -
Michael Taylor 60,161 Reputation points
2023-03-06T15:54:47.17+00:00