CVE-2022-26932
published 2022-05-10CVE-2022-26932: Storage Spaces Direct Elevation of Privilege Vulnerability
PriorityP336high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
EPSS
0.70%
49.0th percentile
Storage Spaces Direct Elevation of Privilege Vulnerability
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server | — | — |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5125 | 10.0.14393.5125 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.2928 | 10.0.17763.2928 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.707 | 10.0.20348.707 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1706 | 10.0.19042.1706 |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_version_20h2 | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f6vh-xhfx-4gv9: Storage Spaces Direct Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-11·CVSS 8.2
CVE-2022-26939 [HIGH] CWE-269 GHSA-f6vh-xhfx-4gv9: Storage Spaces Direct Elevation of Privilege Vulnerability
Storage Spaces Direct Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-26932, CVE-2022-26938.
GHSA
GHSA-fvfx-9cwq-v7v5: Storage Spaces Direct Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-11·CVSS 7.0
CVE-2022-26932 [HIGH] GHSA-fvfx-9cwq-v7v5: Storage Spaces Direct Elevation of Privilege Vulnerability
Storage Spaces Direct Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-26938, CVE-2022-26939.
GHSA
GHSA-9jhm-23m7-2925: Storage Spaces Direct Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-11·CVSS 8.2
CVE-2022-26938 [HIGH] CWE-269 GHSA-9jhm-23m7-2925: Storage Spaces Direct Elevation of Privilege Vulnerability
Storage Spaces Direct Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-26932, CVE-2022-26939.
Microsoft
Storage Spaces Direct Elevation of Privilege Vulnerability
vendor_msrc·2022-05-10·CVSS 8.2
CVE-2022-26932 [HIGH] Storage Spaces Direct Elevation of Privilege Vulnerability
Storage Spaces Direct Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
In this case, a successful attack could be performed from a low privilege AppContainer. The attacker could elevate their privileges and execute code or access resources at a higher integrity level than that of the AppContainer execution environment.
FAQ: According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires the attacker or targeted user to have specific elevated privileges. As is best practice, regular validation and audits of administrative groups should be conducted.
Windows Storag
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-10
Published