CVE-2022-29122
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published May 10, 2022
Updated: Jan 2, 2025
Summary
CVE-2022-29122 is a newly disclosed vulnerability that affects Microsoft Windows Clustered Shared Volumes (CSV). This issue permits an unauthenticated attacker to gain sensitive information through specially crafted requests, potentially leading to unauthorized access or system compromise. The vulnerability arises due to inadequate input validation in the CSV file system driver. Organizations using Windows Server with Clustered Shared Volumes are advised to apply the available patch as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2012
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
- Microsoft Windows Server
- Microsoft Windows Server 2012 R2
Affected Vendors
- Microsoft