CVE-2022-30165

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jun 15, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-30165 is a newly disclosed Windows Kerberos Elevation of Privilege vulnerability. Successful exploitation of this flaw allows an attacker to elevate their user privileges to that of a local system administrator, granting them increased access to sensitive data and system functions. The vulnerability arises due to improper handling of certain Kerberos authentication requests. Microsoft has released a security update to address the issue and urges users to install it as soon as possible to mitigate the risk of potential attacks. This elevation of privilege vulnerability could lead to significant damage if exploited in a targeted attack against unpatched Windows systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows Server 2016
  • Windows Server 2022
  • Microsoft Windows Server 2019
  • Microsoft Windows 11

Affected Vendors

  • Microsoft