PT-2022-5374 · Microsoft · Windows

Angelboy

·

Published

2022-10-11

·

Updated

2025-01-02

·

CVE-2022-38043

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Windows (affected versions not specified)
Description The issue is related to the implementation of the Microsoft Security Support Provider Interface (SSPI) in the Windows operating system, which is associated with access control weaknesses. Exploitation of this issue may allow a remote attacker to disclose protected information using a specially crafted request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-06688
CVE-2022-38043

Affected Products

Windows