/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft and CISA warn users about DogWalk, a now-patched actively exploited RCE vulnerability in Windows 7, 10, 11, and Server 2008 through 2022

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two more flaws to its catalog of Known Exploited Vulnerabilities, based on evidence of active exploitation. Source: Microsoft .

BleepingComputer Ionut Ilascu

Context & Ripple Effects

DogWalk follows a June report that Microsoft had classified a separate Windows RCE as critical while it remained unpatched despite active exploitation. Microsoft’s earlier fixes for a critical wormable Windows flaw and an actively exploited Internet Explorer RCE show a recurring security burden across Windows and Windows Server releases.

CISA’s addition of DogWalk to the Known Exploited Vulnerabilities catalog pairs the patch with an explicit exploitation signal, raising its urgency for organizations running the affected Windows versions.

First-order effects

  • Windows 7, 10, 11, and Server 2008–2022 users have a patch available for DogWalk, while administrators must treat the flaw as an active-exploitation remediation task.
  • CISA’s catalog entry gives defenders a common priority marker for DogWalk alongside Microsoft’s fix.

Second-order effects

  • Enterprise security teams must shift patch-management attention toward DogWalk, potentially displacing lower-priority Windows maintenance work.
  • Microsoft’s affected Windows and Server estate faces renewed scrutiny from customers over how quickly critical RCE reports progress from disclosure to a fix, following the earlier unpatched critical Windows RCE report.

Third-order effects

  • The pattern reinforces CISA’s exploited-vulnerability catalog as a practical bridge between vendor patch releases and enterprise remediation priorities.
  • Repeated actively exploited RCE fixes across Windows point toward more security operations organized around exploitation evidence, rather than severity ratings alone.

The trend: Windows vulnerability response is increasingly being shaped by the combination of vendor patches and CISA’s exploitation-based prioritization.

Discussion

  • @spoofyroot Johnathan Norman on x
    We finally fixed the #DogWalk vulnerably. Sadly this remained an issue for far too long. thanks to everyone who yelled at us to fix it @j00sean @ImreRad
  • @windowsupdate @windowsupdate on x
    As of August 9, 2022, all editions of Windows Server, version 20H2 have reached end of servicing. https://docs.microsoft.com/...
  • @wdormann @wdormann on x
    By now Microsoft has fixed both Follina CVE-2022-30190 and Dogwalk CVE-2022-34713 programming flaws. But please don't forget that MSDT .diagcab files BY DESIGN will run code with a single click. With a UAC bypass if logged in as an admin. This still works. https://github.com/... …
  • @brdpoker Cliff Fisher on x
    As of now, you should be on Server 2019 or Server 2022 for mainstream support. If you're not, you should make plans to test & deploy directly to Server 2022. https://twitter.com/...
  • @j00sean @j00sean on x
    CVE-2022-34713... “...This bug also allows code execution when MSDT is called using the URL protocol from a calling application, typically Microsoft Word...” 🤔 #DogWalk or any #DogWalk variant? For real? I'd like to watch this, seriously... https://twitter.com/...