CVE-2022-35828 is an Elevation of Privilege vulnerability affecting Microsoft Defender for Endpoint on Mac. This high-severity flaw, with a CVSS score of 7.8, allows a local attacker to gain elevated privileges with low attack complexity and no user interaction, potentially leading to full compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog or having public exploit code, it was addressed in Microsoft's September 2022 Patch Tuesday and has seen limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:defender_for_endpoint:-:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.