CVE-2022-23265 is a Remote Code Execution (RCE) vulnerability affecting Microsoft Defender for IoT. This high-severity flaw, with a CVSS score of 8.8, allows an authenticated attacker to execute arbitrary code remotely over the network with low attack complexity. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog, its FAUCET Risk Score of 80/100 indicates significant potential impact. Community discussion and media coverage suggest moderate attention, with one article noting its inclusion in Microsoft's March 2022 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 22.1.2CPE matchmatch criteria | cpe:2.3:a:microsoft:defender_for_iot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.