CVE-2022-30147
CVSS 2.0 Score 7.2 of 10 (high)
Details
Summary
CVE-2022-30147 is a newly disclosed vulnerability affecting Windows Installer. This elevation of privilege issue allows an attacker to gain higher system privileges by manipulating a specially crafted MSI (Microsoft Installer) package. Successful exploitation could lead to the installation of unauthorized software, or the execution of malicious code with administrative rights. Users are advised to install the available patch as soon as possible to mitigate the risk. Microsoft released a security update addressing this vulnerability and urges all Windows users to apply it promptly to protect their systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2008
- Microsoft Windows 7
- Microsoft Windows 10
- Microsoft Windows 8.1
- Microsoft Windows Server 2012
Affected Vendors
- Microsoft