PT-2022-2927 · Microsoft · Windows

Jeongoh Kyea

·

Published

2022-02-05

·

Updated

2023-08-08

·

CVE-2022-24479

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows (affected versions not specified)
Description The issue is related to the DiagTrack service in Microsoft Windows, which has insufficient access restrictions. This can be exploited by an attacker to elevate their privileges using a specially crafted link. It is an elevation-of-privilege vulnerability that allows attackers to affect the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2022-03528
CVE-2022-24479
ZDI-22-808

Affected Products

Windows