CVE-2022-38022
CVSS 3.1 Score 3.3 of 10 (low)
Details
Summary
CVE-2022-38022 is a newly disclosed Windows Kernel vulnerability that could allow an attacker to elevate their privileges, potentially granting them administrative access to a system. This vulnerability exists due to an improper access control issue within the Windows Kernel. An attacker could exploit this flaw through a specially crafted application or file, resulting in a significant increase in attack surface for threat actors. Microsoft is releasing a security update to address this issue, and it is strongly recommended that users install this patch as soon as possible to protect against potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2008
- Microsoft Windows 7
- Microsoft Windows 10
- Microsoft Windows 8.1
- Microsoft Windows Server 2012
Affected Vendors
- Microsoft