⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2022-24481Improper Privilege Management in Microsoft Windows 10 Version 1507

Severity
7.8HIGHNVD
EPSS
44.0%
top 2.45%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedApr 15
Latest updateApr 16

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages21 packages

CVEListV5microsoft/windows_76.1.06.1.7601.25924
CVEListV5microsoft/windows_8.16.3.06.3.9600.20337
CVEListV5microsoft/windows_server_20126.2.9200.06.2.9200.23679
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.5066
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.2803

🔴Vulnerability Details

3
GHSA
GHSA-fcmw-94mj-87r8: Windows Common Log File System Driver Elevation of Privilege Vulnerability2022-04-16
CVEList
Windows Common Log File System Driver Elevation of Privilege Vulnerability2022-04-15
VulnCheck
Windows Common Log File System Driver Elevation of Privilege Vulnerability2022

📋Vendor Advisories

1
Microsoft
Windows Common Log File System Driver Elevation of Privilege Vulnerability2022-04-12
CVE-2022-24481 — Improper Privilege Management | cvebase