CVE-2022-30154Improper Privilege Management in Microsoft Windows Server 2012

Severity
5.3MEDIUMNVD
EPSS
2.9%
top 13.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 15
Latest updateJun 16

Description

Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages8 packages

CVEListV5microsoft/windows_server_20126.2.9200.06.2.9200.23736
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.5192
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.3046
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.770
CVEListV5microsoft/windows_server_2012_r26.3.9600.06.3.9600.20402

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wvgr-fcfh-4f5q: Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability2022-06-16
CVEList
Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability2022-06-15

📋Vendor Advisories

1
Microsoft
Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability2022-06-14
CVE-2022-30154 — Improper Privilege Management | cvebase