CVE-2022-37974Resource Exposure in Microsoft Windows 10 Version 21h1

CWE-668Resource Exposure4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
10.8%
top 6.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateOct 12

Description

Windows Mixed Reality Developer Tools Information Disclosure Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5microsoft/windows_10_version_21h110.0.010.0.19043.2130
CVEListV5microsoft/windows_10_version_21h210.0.19043.010.0.19044.2130
CVEListV5microsoft/windows_11_version_21h210.0.010.0.22000.1098
CVEListV5microsoft/windows_11_version_22h210.0.22621.010.0.22621.674
NVDmicrosoft/windows_1020h2, 21h1, 21h2+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qv68-c8r2-qjc7: Windows Mixed Reality Developer Tools Information Disclosure Vulnerability2022-10-12
CVEList
Windows Mixed Reality Developer Tools Information Disclosure Vulnerability2022-10-11

📋Vendor Advisories

1
Microsoft
Windows Mixed Reality Developer Tools Information Disclosure Vulnerability2022-10-11
CVE-2022-37974 — Resource Exposure in Microsoft | cvebase