CVE-2022-30160

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 15, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-30160 is a newly disclosed Windows vulnerability that allows an attacker to elevate privileges through the Advanced Local Procedure Call (ALPC) interface. By manipulating specific ALPC messages, an unprivileged process can gain SYSTEM-level access, which could lead to serious system compromises. This issue can be exploited locally and affect Windows Servers 2008 and later, as well as Windows 10 and later. Users are advised to apply the Microsoft Security Bulletin MS16-032 patch, which addresses a similar vulnerability, as a temporary mitigation measure until a specific patch for CVE-2022-30160 becomes available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008
  • Microsoft Windows 7
  • Microsoft Windows 10
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012

Affected Vendors

  • Microsoft