CVE-2022-37997

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 11, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-37997 is a newly disclosed Windows Graphics Component vulnerability that grants attackers elevated privileges. Successful exploitation of this EoP (Elevation of Privilege) flaw allows attackers to gain administrative access to affected systems, potentially leading to significant data loss or unauthorized system modifications. The vulnerability is reportedly due to a programming error in the handling of certain graphics files. Microsoft has released a patch to address this issue, and it is strongly recommended that users install it as soon as possible to safeguard their systems. Failure to apply the patch could expose organizations to potential security breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008
  • Microsoft Windows 7
  • Microsoft Windows 10
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012

Affected Vendors

  • Microsoft