Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-50238

Опубликовано: 08 сент. 2025
Источник: nvd
CVSS3: 7.4
CVSS3: 6.7
EPSS Низкий

Описание

The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online list have been excluded from the on-endpoint blocklist longer than the expected periodic monthly Windows updates. It is possible to fully synchronize the driver blocklist using WDAC policies. NOTE: The vendor explains that Windows Update provides a smaller, compatibility-focused driver blocklist for general users, while the full XML list is available for advanced users and organizations to customize at the risk of usability issues.

EPSS

Процентиль: 13%
0.00043
Низкий

7.4 High

CVSS3

6.7 Medium

CVSS3

Дефекты

CWE-820
CWE-184

Связанные уязвимости

CVSS3: 7.4
github
5 месяцев назад

The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online list have been excluded from the on-endpoint blocklist longer than the expected periodic monthly Windows updates. It is possible to fully synchronize the driver blocklist using WDAC policies. NOTE: The vendor explains that Windows Update provides a smaller, compatibility-focused driver blocklist for general users, while the full XML list is available for advanced users and organizations to customize at the risk of usability issues.

EPSS

Процентиль: 13%
0.00043
Низкий

7.4 High

CVSS3

6.7 Medium

CVSS3

Дефекты

CWE-820
CWE-184