CVE-2022-38022

CVSS 3.1 Score 3.3 of 10 (low)

Details

Published Oct 11, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-38022 is a newly disclosed Windows Kernel vulnerability that could allow an attacker to elevate their privileges, potentially granting them administrative access to a system. This vulnerability exists due to an improper access control issue within the Windows Kernel. An attacker could exploit this flaw through a specially crafted application or file, resulting in a significant increase in attack surface for threat actors. Microsoft is releasing a security update to address this issue, and it is strongly recommended that users install this patch as soon as possible to protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008
  • Microsoft Windows 7
  • Microsoft Windows 10
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012

Affected Vendors

  • Microsoft