PT-2025-36472 · Microsoft · Windows+1

Published

2025-09-08

·

Updated

2025-11-17

·

CVE-2022-50238

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Microsoft Windows (affected versions not specified)
Description: The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online list have been excluded from the on-endpoint blocklist longer than the expected periodic monthly Windows updates. It is possible to fully synchronize the driver blocklist using Windows Defender Application Control (WDAC) policies. The vendor explains that Windows Update provides a smaller, compatibility-focused driver blocklist for general users, while the full XML list is available for advanced users and organizations to customize at the risk of usability issues.
Recommendations: Fully synchronize the driver blocklist using WDAC policies.

Fix

Incomplete List of Disallowed Inputs

Weakness Enumeration

Related Identifiers

CVE-2022-50238

Affected Products

Windows
Windows Defender Application Control