CVE-2022-30165
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2022-30165 is a newly disclosed Windows Kerberos Elevation of Privilege vulnerability. Successful exploitation of this flaw allows an attacker to elevate their user privileges to that of a local system administrator, granting them increased access to sensitive data and system functions. The vulnerability arises due to improper handling of certain Kerberos authentication requests. Microsoft has released a security update to address the issue and urges users to install it as soon as possible to mitigate the risk of potential attacks. This elevation of privilege vulnerability could lead to significant damage if exploited in a targeted attack against unpatched Windows systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows Server 2016
- Windows Server 2022
- Microsoft Windows Server 2019
- Microsoft Windows 11
Affected Vendors
- Microsoft