CVE-2022-38007 is an Elevation of Privilege vulnerability affecting Microsoft Azure Guest Configuration and Azure Arc-enabled servers. With a CVSS score of 7.8 (HIGH), this vulnerability allows a local attacker to gain elevated privileges with low attack complexity, leading to high impact on confidentiality, integrity, and availability. While Microsoft has patched this flaw, there is no public exploit code available, nor is it listed in CISA's KEV catalog, though it was mentioned in a BleepingComputer article regarding Microsoft's September 2022 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_arc:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_guest_configuration:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.