CVE-2022-29150

CVSS 3.1 Score 7 of 10 (high)

Details

Published May 10, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-29150 is a newly disclosed vulnerability affecting Windows Cluster Shared Volumes (CSV). This elevation of privilege issue grants attackers unauthorized access to CSVs with administrative privileges, allowing them to execute malicious code and potentially take control of the affected system. Successful exploitation depends on an attacker having valid logon credentials, but the severity is high due to the potential impact on critical data and system functionality. Microsoft has released a patch to address this vulnerability, and it is strongly recommended that all affected systems be updated promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2016
  • Windows Server 2022
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2012 R2

Affected Vendors

  • Microsoft