CVE-2022-29799 is a directory traversal vulnerability in networkd-dispatcher, affecting Microsoft Windows Defender for Endpoint. The flaw, stemming from unsanitized functions, allows an attacker to escape the base directory. Rated Medium (CVSS 5.5), it requires local access and could lead to high confidentiality impact. While not actively exploited or on the KEV catalog, it has garnered significant community discussion and media coverage, indicating awareness of its potential. No public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:windows_defender_for_endpoint:*:*:*:*:*:linux:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.