CVE-2022-37982Code Injection in Microsoft Windows 10 Version 1507

CWE-94Code Injection4 documents4 sources
Severity
8.8HIGHNVD
EPSS
12.5%
top 6.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateOct 12

Description

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages21 packages

CVEListV5microsoft/windows_server_20126.2.9200.06.2.9200.23920
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.5427
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.3532
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.1129
CVEListV5microsoft/windows_server_2012_r26.3.9600.06.3.9600.20625

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jpv2-v6m7-7mg4: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability2022-10-12
CVEList
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability2022-10-11

📋Vendor Advisories

1
Microsoft
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability2022-10-11
CVE-2022-37982 — Code Injection in Microsoft | cvebase