CVE-2022-35828
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2022-35828 is a newly disclosed vulnerability affecting Microsoft Defender for Endpoint on Mac devices. This elevation of privilege issue allows an attacker to gain higher system privileges, potentially enabling them to install unauthorized software, modify or delete sensitive data, or take control of the affected system. The vulnerability occurs due to insufficient input validation, enabling an attacker to manipulate certain files and exploit the weakness in the application. Microsoft has released a patch to address this vulnerability, and users are strongly encouraged to install it to safeguard their systems from potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Defender for Endpoint
Affected Vendors
- Microsoft