PT-2022-5363 · Microsoft · Windows Client Server Run-Time Subsystem+1

Simon Zuckerbraun

·

Published

2022-10-11

·

Updated

2025-01-02

·

CVE-2022-37989

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Client Server Run-time Subsystem (CSRSS) (affected versions not specified)
Description The issue is related to an elevation of privilege vulnerability in the Windows Client Server Run-time Subsystem (CSRSS). It is associated with an uncontrolled DLL search path. Exploitation of this issue may allow an attacker to execute arbitrary code. The vulnerability can be used by attackers to affect the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2022-06677
CVE-2022-37989
ZDI-22-1413

Affected Products

Windows
Windows Client Server Run-Time Subsystem