References https://nvd.nist.gov/vuln/detail/CVE-2022-44690 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-44690 https://www.rapid7.com/db/vulnerabilities/msft-cve-2022-44690/ https://www.invicti.com/web-application-vulnerabilities/sharepoint-cve-2022-44690-vulnerability-cve-2022-44690 https://www.acunetix.com/vulnerabilities/web/sharepoint-cve-2022-44690-vulnerability-cve-2022-44690 https://docs.sophos.com/releasenotes/output/en-us/nsg/ipsreleasenotes/7.20.16_s.pdf https://docs.sophos.com/releasenotes/output/en-us/nsg/ipsreleasenotes/9.20.16_s.pdf https://www.sonicwall.com/blog/microsoft-security-bulletin-coverage-for-december-2022 https://www.cve.org/CVERecord?id=CVE-2022-44690
Related VulnerabilitiesPoCCVE-2026-10768: Drupal LocalGov Workflows < 1.6.0 - Information DisclosurePoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)PoC全程云OA /oa/Common/WF/WorkFlow/WorkFlow.asmx SQL 注入漏洞孚盟云CRM WorkFlowHandler.ashx 存在SQL注入漏洞PoCargo-workflows-unauth: Argo Workflows - Unauthenticated DashboardPoCdagu-rce: Dagu Workflow Engine - Remote Code ExecutionPoC用友 NC /portal/pt/servlet/workflowImageServlet/doPost SQL 注入漏洞PoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoC九思OA /jsoa/workflow/dwr/exec/workflowSync.getUserStatusByRole.dwr SQL 注入漏洞