CVE-2022-35762 is an Elevation of Privilege vulnerability affecting Microsoft Windows 10, Windows Server 2016, 2019, and 2022, specifically within Storage Spaces Direct. With a CVSS score of 7.8 (High), a local attacker with low privileges can exploit this with low attack complexity to gain full control over the system, impacting confidentiality, integrity, and availability. While not currently listed on CISA's KEV catalog or having public exploit code in Metasploit or ExploitDB, it was addressed in the August 2022 Patch Tuesday, indicating its significance. Community discussion and media coverage are relatively low, suggesting it hasn't garnered widespread attention despite its critical impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:arm64:* | ||
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:x64:* | ||
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:x86:* | ||
21h1CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:arm64:* | ||
21h1CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.