Microsoft released fixes for critical remote code execution vulnerabilities in the Windows RPC Runtime, including CVE-2022-26809, a flaw in rpcrt4.dll that could allow unauthenticated, zero-click code execution on vulnerable systems. Security reporting said the bug stemmed from an integer overflow that could lead to a heap buffer overflow during RPC processing, affecting both client-side and server-side code paths in Windows.
Researchers warned that unpatched systems exposing TCP port 445 were at particular risk, with internet scanning indicating that more than 700,000 Windows machines could be reachable and potentially vulnerable. Microsoft’s April security updates addressed the issue, while defenders were urged to apply patches, block external access to port 445, and restrict inbound connections to reduce exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
As of April 18, 2022, Shodan data cited in reporting showed more than 700,000 internet-exposed Windows machines with TCP port 445 open that were potentially vulnerable if unpatched. The count highlighted the broad exposure of systems affected by CVE-2022-26809.
Akamai researchers Ophir Harpaz and Ben Barnea published analysis of the critical Windows RPC runtime vulnerability CVE-2022-26809, describing how an integer overflow in rpcrt4.dll could lead to heap buffer overflow and remote code execution. The analysis also discussed mitigations such as restricting or blocking external access to TCP port 445.
Microsoft released April 2022 security updates that patched three critical vulnerabilities in the Windows RPC runtime, including CVE-2022-26809. The flaw could allow unauthenticated remote code execution on vulnerable systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
fourcore.io
Open sourceakamai.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.