CVE-2022-29800 is a time-of-check-time-of-use (TOCTOU) race condition in networkd-dispatcher, allowing an attacker to replace scripts believed to be root-owned with malicious ones. Although the provided data incorrectly lists "microsoft windows_defender_for_endpoint" as an affected product, this vulnerability primarily impacts Linux systems utilizing networkd-dispatcher. With a CVSS score of 4.7 (Medium), it requires local access and high attack complexity, but can lead to high integrity impacts. There is no public exploit code available, nor is it listed on the KEV catalog, indicating it is not actively exploited. However, it has garnered significant community discussion and media coverage, suggesting awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:windows_defender_for_endpoint:-:*:*:*:*:linux:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.