CVE-2022-30166

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 15, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-30166 is an elevation of privilege vulnerability affecting the Local Security Authority Subsystem Service. An attacker who successfully exploits this vulnerability can gain administrative privileges on the affected system. This issue can potentially allow an attacker to install programs, view, modify or delete data, and create new accounts with full user rights. The vulnerability is considered serious as it can lead to a complete system compromise if exploited. It is recommended that affected systems be patched as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008
  • Microsoft Windows 7
  • Microsoft Windows 10
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012

Affected Vendors

  • Microsoft