CVE-2022-37971
published 2022-10-11CVE-2022-37971: Microsoft Windows Defender Elevation of Privilege Vulnerability
PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.61%
45.4th percentile
Microsoft Windows Defender Elevation of Privilege Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | malware_protection_engine | < 1.1.19700.2 | 1.1.19700.2 |
| microsoft | microsoft_malware_protection_engine | >= 1.1.0.0 < 1.1.19700.2 | 1.1.19700.2 |
| msrc | microsoft_malware_protection_engine | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens RUGGEDCOM CROSSBOW
cisa_ics·2023-08-10·CVSS 7.5
[HIGH] Siemens RUGGEDCOM CROSSBOW
ICS Advisory
##
Siemens RUGGEDCOM CROSSBOW
Release DateAugust 10, 2023
Alert CodeICSA-23-222-05
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM CROSSBOW
- Vulnerabilities: Out-of-bounds Read, Improper Privilege Management, SQL Injection, Missing Authentication for Critical Function
## 2. RISK EVALUATION
Successful exploitation of these vulnerabiliti
Microsoft
Microsoft Windows Defender Elevation of Privilege Vulnerability
vendor_msrc·2022-10-11·CVSS 7.1
CVE-2022-37971 [HIGH] Microsoft Windows Defender Elevation of Privilege Vulnerability
Microsoft Windows Defender Elevation of Privilege Vulnerability
FAQ: Where can I find more information about NTLM relay attacks?
Download Mitigating Pass the Hash (PtH) Attacks and Other Credential Theft, Version 1 and 2. This document discusses Pass-the-Hash (PtH) attacks against the Windows operating systems and provides holistic planning strategies that, when combined with the Windows security features, will provide a more effective defense against pass-the-hash attacks.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to no loss of confidentiality (C:N) but have major impact on integrity (I:H) and on availability (A:H). What does that mean for this vulnerability?
This vulnerability does not allow disclosure of any confidential information,
GHSA
GHSA-gqj6-qxwh-7f6p: Microsoft Windows Defender Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-10-12
CVE-2022-37971 [HIGH] CWE-269 GHSA-gqj6-qxwh-7f6p: Microsoft Windows Defender Elevation of Privilege Vulnerability
Microsoft Windows Defender Elevation of Privilege Vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-11
Published