CVE-2022-35828

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Sep 13, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-35828 is a newly disclosed vulnerability affecting Microsoft Defender for Endpoint on Mac devices. This elevation of privilege issue allows an attacker to gain higher system privileges, potentially enabling them to install unauthorized software, modify or delete sensitive data, or take control of the affected system. The vulnerability occurs due to insufficient input validation, enabling an attacker to manipulate certain files and exploit the weakness in the application. Microsoft has released a patch to address this vulnerability, and users are strongly encouraged to install it to safeguard their systems from potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Defender for Endpoint

Affected Vendors

  • Microsoft