PT-2022-5508 · Microsoft · Azure Iot Edge For Linux On Windows+1

Published

2022-11-08

·

Updated

2023-06-14

·

CVE-2022-38014

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Subsystem for Linux (WSL2) (affected versions not specified) Azure IoT Edge for Linux on Windows (EFLOW) (affected versions not specified)
Description The issue is related to synchronization errors when using a shared resource in the kernel subsystem for running Linux applications. This could allow an attacker to elevate their privileges.
Recommendations For Windows Subsystem for Linux (WSL2), at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Azure IoT Edge for Linux on Windows (EFLOW), at the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2022-06837
CVE-2022-38014

Affected Products

Azure Iot Edge For Linux On Windows
Windows Subsystem For Linux