CVE-2022-29138

CVSS 3.1 Score 7.0 of 10 (high)

Details

Published May 10, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-29138 is a newly disclosed vulnerability that affects Windows Clustered Shared Volumes (CSV). This elevation of privilege (EoP) issue grants attackers system-level access to a vulnerable system upon successful exploitation. An attacker could potentially use this vulnerability to escalate their privileges and execute arbitrary code with administrative rights. The exploitation of this bug requires the attacker to have valid login credentials and access to a CSV on the target machine. Microsoft has released a security advisory and a patch to address this issue. It is strongly recommended that all affected systems are updated promptly to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2016
  • Windows Server 2022
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2012 R2

Affected Vendors

  • Microsoft