CVE-2022-29123

CVSS 2.0 Score 2.1 of 10 (low)

Details

Published May 10, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-29123 is a vulnerability impacting Windows Clustered Shared Volumes. This issue enables an unauthenticated attacker to obtain sensitive information through specially crafted requests, potentially leading to data leakage. The flaw lies in the Cluster Shared Volume File System (CSVFS) driver, which fails to verify the authenticity of certain requests, allowing unauthorized access to metadata. Microsoft has released a patch to address this vulnerability, urging users to install it to mitigate potential risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Windows Server 2022
  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2012 R2

Affected Vendors

  • Microsoft