Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/167754/Windows-LSA-Service-LsapGetClientInfo-Impersonation-Level-Check-Privilege-Escalation.html | Third Party Advisory VDB Entry |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-30166 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
20 Dec 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) Local Security Authority Subsystem Service Elevation of Privilege Vulnerability |
27 Oct 2022, 16:04
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) http://packetstormsecurity.com/files/167754/Windows-LSA-Service-LsapGetClientInfo-Impersonation-Level-Check-Privilege-Escalation.html - Third Party Advisory, VDB Entry |
15 Jul 2022, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
27 Jun 2022, 18:02
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 4.6
v3 : 7.8 |
CPE | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:azure:*:*:* cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2012:-:r2:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2016:20h2:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* |
|
First Time |
Microsoft windows 7
Microsoft windows Server 2022 Microsoft windows Server 2019 Microsoft windows Rt 8.1 Microsoft windows Server 2012 Microsoft windows 10 Microsoft windows 8.1 Microsoft windows Server 2008 Microsoft Microsoft windows 11 Microsoft windows Server 2016 |
|
References | (MISC) https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-30166 - Patch, Vendor Advisory | |
CWE | NVD-CWE-noinfo |
15 Jun 2022, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-06-15 22:15
Updated : 2023-12-20 22:15
NVD link : CVE-2022-30166
Mitre link : CVE-2022-30166
CVE.ORG link : CVE-2022-30166
JSON object : View
Products Affected
microsoft
- windows_8.1
- windows_10
- windows_server_2022
- windows_server_2019
- windows_rt_8.1
- windows_server_2016
- windows_server_2008
- windows_server_2012
- windows_7
- windows_11
CWE