CVE-2022-37983

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 11, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-37983 is an elevation of privilege vulnerability affecting Microsoft's Desktop Window Manager (DWM) Core Library. Malicious actors can exploit this vulnerability to gain higher system privileges, potentially leading to the compromise of the affected system. The exact cause of the issue is a flaw in the way DWM handles objects in memory, which can be manipulated to escalate user privileges. Microsoft has released a patch to address this vulnerability, and it is recommended that users install it as soon as possible to protect against potential attacks. Failure to address this vulnerability could result in unauthorized access to sensitive information or system modifications.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Windows Server 2022
  • Microsoft Windows 11
  • Microsoft Windows Server 2019

Affected Vendors

  • Microsoft