CVE-2022-44689

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Dec 13, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-44689 is a kernel elevation of privilege vulnerability affecting Windows Subsystem for Linux (WSL2). An attacker who successfully exploits this flaw can gain administrative privileges on the host system, bypassing WSL2's security boundaries. This vulnerability poses a serious risk, as it allows an unauthenticated, remote attacker to compromise WSL2 and ultimately gain control over the entire system. Microsoft has released a patch to address this issue, and it is recommended that all WSL2 users install the update as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Windows Server 2022
  • Microsoft Windows 11
  • Microsoft Windows Server 2019

Affected Vendors

  • Microsoft