CVE-2022-30150

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jun 15, 2022
Updated: Jan 2, 2025
CWE ID 287

Summary

CVE-2022-30150 is a newly discovered vulnerability affecting Windows Defender's Remote Credential Guard. Hackers can exploit this elevation of privilege issue to bypass the security feature, potentially gaining administrator access to vulnerable systems. Successful exploitation requires a specially crafted file sent to the target via email or other means, posing a significant threat to organizations through phishing attacks. Microsoft has released a patch to address the vulnerability, and users are advised to install it promptly to protect their systems. Unpatched systems remain at risk of compromise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows Server 2016
  • Windows Server 2022
  • Microsoft Windows Server 2019
  • Microsoft Windows 11

Affected Vendors

  • Microsoft