Microsoft security update-CVE-2022-26904
NAME
Microsoft – Windows
- Platforms Affected:
Windows - Risk Level:
high - CVE Type:
Privilege escalation
DESCRIPTION
CVE-2022-26904 is a privilege escalation vulnerability impacting multiple products and versions of Microsoft Windows. A Metasploit module was observed in open source.
CVSS Information:
- CVSS 2.0 SCORE:
- CVSS 3.0 SCORE: 7
- Exploit Disclosed in the Public:
true - Exploit Weaponised:
true - PoC Link:
hXXps://github[.]com//rapid7/metasploit-framework/blob/c252faf9388449dd3af4f0ab1288c0ce82fe4cf9/modules/exploits/windows/local/cve_2022_26904_superprofile[.]rb
MITIGATION
Microsoft addressed the vulnerability in a security advisory with a patch.
- Reference Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26904 - Patch Available:
available
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.