CVE-2022-30164
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2022-30164 is a newly disclosed vulnerability affecting the Kerberos AppContainer security feature. This issue allows an attacker to bypass the containment policy of AppContainer, thereby gaining unauthorized access to sensitive information or resources within a system. The vulnerability is significant as it undermines the security measures intended to isolate applications and limit their access to critical system components. Successful exploitation of this vulnerability could lead to escalation of privileges and potentially serious consequences, including data theft or system compromise. Microsoft has released a patch to address this issue and it is strongly recommended that all affected systems be updated as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2008
- Microsoft Windows 7
- Microsoft Windows 10
- Microsoft Windows 8.1
- Microsoft Windows Server 2012
Affected Vendors
- Microsoft