Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2022-35760

Опубликовано: 09 авг. 2022
Источник: msrc
CVSS3: 7.8
EPSS Низкий

Описание

Microsoft ATA Port Driver Elevation of Privilege Vulnerability

FAQ

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?

This vulnerability could be triggered when a windows client connects to a malicious remote share.

What privileges could be gained by an attacker who successfully exploited the vulnerability?

A domain user could use this vulnerability to elevate privileges to SYSTEM assigned integrity level.

Обновления

ПродуктСтатьяОбновление
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2012
Windows Server 2012 (Server Core installation)
Windows 8.1 for 32-bit systems
Windows 8.1 for x64-based systems
Windows Server 2012 R2
Windows RT 8.1
-

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 52%
0.00286
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
почти 3 года назад

Microsoft ATA Port Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
github
почти 3 года назад

Microsoft ATA Port Driver Elevation of Privilege Vulnerability.

CVSS3: 7.8
fstec
почти 3 года назад

Уязвимость драйвера ATA Port операционной системы Windows, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 52%
0.00286
Низкий

7.8 High

CVSS3