CVE-2022-34723 is an information disclosure vulnerability affecting Windows DPAPI in Microsoft Windows 11. This medium-severity flaw (CVSS 5.5) allows a local attacker with low privileges to disclose sensitive information without user interaction, potentially leading to a compromise of confidentiality. While there is no public exploit code or significant community discussion, it was addressed in the September 2022 Patch Tuesday, indicating it may have been actively exploited as a zero-day.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:arm64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.