CVE-2022-37976 — Improper Privilege Management in Microsoft Windows Server 2008 R2 Service Pack 1
Severity
8.8HIGHNVD
EPSS
15.9%
top 5.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 11
Latest updateOct 12
Description
Active Directory Certificate Services Elevation of Privilege Vulnerability
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages16 packages
Patches
🔴Vulnerability Details
1GHSA▶
GHSA-8vr2-6v7f-c42x: Active Directory Certificate Services Elevation of Privilege Vulnerability↗2022-10-12
📋Vendor Advisories
1🕵️Threat Intelligence
7Qualys▶
October 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities With 13 Critical, Plus 12 Microsoft Edge (Chromium-Based); Adobe Releases 4 Advisories, 29 Vulnerabilities With 17 Critical. | Qualys↗2022-10-11
Qualys▶
October 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities With 13 Critical, Plus 12 Microsoft Edge (Chromium-Based); Adobe Releases 4 Advisories, 29 Vulnerabilities With 17 Critical.↗2022-10-11
Talos
▶
Talos
▶