CVE-2022-23286 is an Elevation of Privilege vulnerability affecting the Windows Cloud Files Mini Filter Driver across various Windows operating systems, including Windows 10, 11, and Server versions. With a CVSS score of 7.0 (HIGH), this vulnerability requires low privileges and high attack complexity, but successful exploitation could lead to high confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation, readily available exploit code, or KEV listing, the vulnerability has garnered significant community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:*:* | ||
21h1CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:*:* | ||
21h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:*:* | ||
1809CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* | ||
1909CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.