CVE-2022-30147

CVSS 2.0 Score 7.2 of 10 (high)

Details

Published Jun 15, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-30147 is a newly disclosed vulnerability affecting Windows Installer. This elevation of privilege issue allows an attacker to gain higher system privileges by manipulating a specially crafted MSI (Microsoft Installer) package. Successful exploitation could lead to the installation of unauthorized software, or the execution of malicious code with administrative rights. Users are advised to install the available patch as soon as possible to mitigate the risk. Microsoft released a security update addressing this vulnerability and urges all Windows users to apply it promptly to protect their systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008
  • Microsoft Windows 7
  • Microsoft Windows 10
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012

Affected Vendors

  • Microsoft