CVE-2022-30142

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jun 15, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-30142 is a newly disclosed vulnerability affecting Windows File History. Hackers can exploit this remote code execution (RCE) bug to gain unauthorized access to a targeted system. The flaw exists in the way File History service handles symbolic links, allowing an attacker to trick a user into opening a malicious file. Successful exploitation results in the execution of arbitrary code with the privileges of the user running the File History service. Organizations are advised to update their systems as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 7
  • Microsoft Windows 10
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2016

Affected Vendors

  • Microsoft