cbcvebase.
CVE-2022-48386
published 2023-05-09

CVE-2022-48386: the apipe driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed.

PriorityP414medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.09%
0.7th percentile
the apipe driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed.

Affected

9 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
msrcmicrosoft_visual_studio_2017_version_15.9
msrcmicrosoft_visual_studio_2019_version_16.11
msrcmicrosoft_visual_studio_2022_version_17.10
msrcmicrosoft_visual_studio_2022_version_17.12
msrcmicrosoft_visual_studio_2022_version_17.14
msrcmicrosoft_visual_studio_2022_version_17.8
unisoc_technologies_co_ltdsc9863a_sc9832e_sc7731e_t610_t310_t606_t760_t610_t618_t606_t612_t616_t760_t770_t

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
vendor_msrc6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.