CVE-2022-38030

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Oct 11, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-38030 is a newly disclosed information disclosure vulnerability affecting Windows USB Serial Drivers. Attackers can exploit this vulnerability by sending maliciously crafted data to a targeted system via a USB device. Successful exploitation allows the attacker to obtain sensitive information, potentially including kernel memory contents and USB traffic data. This can lead to further system compromise and unauthorized access to confidential data. Users are advised to install the Microsoft Security Advisory MS16-071 to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Windows Server 2022
  • Microsoft Windows 11
  • Microsoft Windows Server 2019

Affected Vendors

  • Microsoft