CVE-2022-38017 is an Elevation of Privilege vulnerability affecting Microsoft StorSimple 8000 Series devices and their firmware. With a CVSS score of 6.8 (Medium), it presents a significant risk as it allows an unauthenticated attacker with physical access to achieve high impact on confidentiality, integrity, and availability. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), the vulnerability was mentioned in Microsoft's October 2022 Patch Tuesday, indicating it was addressed as part of a broader security update. Community discussion and media coverage suggest moderate attention, with one article noting its inclusion in a patch that addressed a zero-day, though not specifically stating this CVE was the zero-day.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:storsimple_8010_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:storsimple_8020_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.