CVE-2022-26938
CVSS 3.1 Score 7.0 of 10 (high)
Details
Summary
CVE-2022-26938 is an elevation of privilege vulnerability affecting Microsoft Storage Spaces Direct. An attacker who exploits this vulnerability can gain unauthorized kernel-mode access, allowing them to potentially install unauthorized software, view, modify, or delete sensitive information, and disrupt the availability of the affected system. Successful exploitation requires an attacker to have valid login credentials and local access to the target system. Microsoft has released a security update to address this vulnerability, and administrators are strongly encouraged to install it as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
- Microsoft Windows Server
Affected Vendors
- Microsoft