CVE-2022-30189
published 2022-06-15CVE-2022-30189: Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability
PriorityP333medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
2.54%
83.2th percentile
Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1766 | 10.0.19042.1766 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1766 | 10.0.19043.1766 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19043.1766 | 10.0.19043.1766 |
| msrc | windows_10_version_20h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_20h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h1_for_32-bit_systems | — | — |
| msrc | windows_10_version_21h1_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h1_for_x64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_21h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability
vendor_msrc·2022-06-14·CVSS 6.5
CVE-2022-30189 [MEDIUM] Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability
Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker would have to send the victim a malicious file that the victim would have to execute.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of confidentiality (C:H)? What does that mean for this vulnerability?
Exploiting this vulnerability will allow an attacker to access resources that are protected by conditional access policies based solely on device compliance state. For more information, please refer to Scenarios for using Conditional Access with Microsoft Intune - Microsoft Intune | Microsoft Docs.
FAQ: To what scenario is t
GHSA
GHSA-rfwm-w9jq-qr63: Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability
ghsa_unreviewed·2022-06-16
CVE-2022-30189 [MEDIUM] GHSA-rfwm-w9jq-qr63: Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability
Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-06-15
Published