PT-2022-1714 · Microsoft · Windows Kernel+1
Published
2022-02-08
·
Updated
2023-08-08
·
CVE-2022-21989
CVSS v3.1
7.8
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows Kernel (affected versions not specified)
Description
The issue is related to insufficient access control in the Windows Kernel, allowing an attacker to elevate their privileges. This vulnerability can be exploited to gain access to resources at a higher integrity level than the AppContainer environment. It is reported that a successful attack can be executed from an AppContainer with low privileges, enabling the attacker to execute code or access resources at a higher level of integrity. The vulnerability affects a wide range of Windows products and components.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Kernel