CVE-2022-30166
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jun 15, 2022
Updated: Jan 2, 2025
Summary
CVE-2022-30166 is an elevation of privilege vulnerability affecting the Local Security Authority Subsystem Service. An attacker who successfully exploits this vulnerability can gain administrative privileges on the affected system. This issue can potentially allow an attacker to install programs, view, modify or delete data, and create new accounts with full user rights. The vulnerability is considered serious as it can lead to a complete system compromise if exploited. It is recommended that affected systems be patched as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2008
- Microsoft Windows 7
- Microsoft Windows 10
- Microsoft Windows 8.1
- Microsoft Windows Server 2012
Affected Vendors
- Microsoft