CVE-2022-29151
CVSS 3.1 Score 7 of 10 (high)
Details
Summary
CVE-2022-29151 is a newly discovered vulnerability affecting Windows Cluster Shared Volumes (CSV). This issue grants an attacker elevated privileges when a specially crafted request is sent to a vulnerable Microsoft Cluster Shared Volume File System (CSVFS) server. Successful exploitation could allow the attacker to gain administrative control over the affected system. The vulnerability can be exploited remotely, making it a serious threat to organizations that use Windows Servers with CSVFS. Microsoft has released a security update to address this vulnerability, and it is recommended that all affected systems be promptly patched to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2012
- Microsoft Windows Server 2016
- Windows Server 2022
- Microsoft Windows Server 2019
- Microsoft Windows Server 2012 R2
Affected Vendors
- Microsoft