Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2022-26932

Опубликовано: 10 мая 2022
Источник: msrc
CVSS3: 8.2
EPSS Низкий

Описание

Storage Spaces Direct Elevation of Privilege Vulnerability

FAQ

According to the CVSS metric, successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?

In this case, a successful attack could be performed from a low privilege AppContainer. The attacker could elevate their privileges and execute code or access resources at a higher integrity level than that of the AppContainer execution environment.

According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability?

Successful exploitation of this vulnerability requires the attacker or targeted user to have specific elevated privileges. As is best practice, regular validation and audits of administrative groups should be conducted.

Обновления

ПродуктСтатьяОбновление
Windows Server 2016
Windows Server 2016 (Server Core installation)
Windows Server 2019
Windows Server 2019 (Server Core installation)
Windows Server, version 20H2 (Server Core Installation)
Windows Server 2022
Windows Server 2022 (Server Core installation)

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 63%
0.00456
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
около 3 лет назад

Storage Spaces Direct Elevation of Privilege Vulnerability

CVSS3: 8.2
github
около 3 лет назад

Storage Spaces Direct Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-26938, CVE-2022-26939.

CVSS3: 8.2
fstec
около 3 лет назад

Уязвимость функции распределенного хранения данных Storage Spaces Direct операционных систем Windows, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 63%
0.00456
Низкий

8.2 High

CVSS3