CVE-2022-24546

Description

Windows DWM Core Library Elevation of Privilege Vulnerability

Risk Information

Base Score
7.7
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.373

Associated Vulnerability

VulnerabilityOS Platform
Win32 Stream Enumeration Remote Code Execution Vulnerability for Windows 10 Version 1909 for x64-based Systems (KB5012591) (CVE-2022-26904) (CVE-2022-24521)Windows
Win32 Stream Enumeration Remote Code Execution Vulnerability for Windows 10 Version 1909 for x86-based Systems (KB5012591) (CVE-2022-26904) (CVE-2022-24521)Windows
Win32 Stream Enumeration Remote Code Execution Vulnerability for Windows 11 for x64-based Systems (KB5012592) (CVE-2022-26904) (CVE-2022-24521)Windows
Win32 Stream Enumeration Remote Code Execution Vulnerability for Windows 10 Version 21H1 for x86-based Systems (KB5012599) (CVE-2022-26904) (CVE-2022-24521)Windows
Win32 Stream Enumeration Remote Code Execution Vulnerability for Windows 10 Version 21H1 for x64-based Systems (KB5012599) (CVE-2022-26904) (CVE-2022-24521)Windows
Win32 Stream Enumeration Remote Code Execution Vulnerability for Windows 10 Version 20H2 for x86-based Systems (KB5012599) (CVE-2022-26904) (CVE-2022-24521)Windows
Win32 Stream Enumeration Remote Code Execution Vulnerability for Windows 10 Version 20H2 for x64-based Systems (KB5012599) (CVE-2022-26904) (CVE-2022-24521)Windows
Win32 Stream Enumeration Remote Code Execution Vulnerability for Windows 10 Version 21H2 for x64-based Systems (KB5012599) (CVE-2022-26904) (CVE-2022-24521)Windows
Win32 Stream Enumeration Remote Code Execution Vulnerability for Windows 10 Version 21H2 for x86-based Systems (KB5012599) (CVE-2022-26904) (CVE-2022-24521)Windows
Win32 Stream Enumeration Remote Code Execution Vulnerability for Microsoft server operating system version 21H2 for x64-based Systems (KB5012604) (CVE-2022-26904) (CVE-2022-24521)Windows
Win32 Stream Enumeration Remote Code Execution Vulnerability for Windows Server 2019 for x64-based Systems (KB5012647) (CVE-2022-26904) (CVE-2022-24521)Windows
Win32 Stream Enumeration Remote Code Execution Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB5012647) (CVE-2022-26904) (CVE-2022-24521)Windows
Win32 Stream Enumeration Remote Code Execution Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB5012647) (CVE-2022-26904) (CVE-2022-24521)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-333992022-04 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB5012591) (CVE-2022-26904) (CVE-2022-24521)
PATCH-334002022-04 Cumulative Update for Windows 10 Version 1909 for x86-based Systems (KB5012591) (CVE-2022-26904) (CVE-2022-24521)
PATCH-333852022-04 Cumulative Update for Windows 11 for x64-based Systems (KB5012592) (CVE-2022-26904) (CVE-2022-24521)
PATCH-333862022-04 Cumulative Update for Windows 10 Version 21H1 for x86-based Systems (KB5012599) (CVE-2022-26904) (CVE-2022-24521)
PATCH-333872022-04 Cumulative Update for Windows 10 Version 21H1 for x64-based Systems (KB5012599) (CVE-2022-26904) (CVE-2022-24521)
PATCH-333882022-04 Cumulative Update for Windows 10 Version 20H2 for x86-based Systems (KB5012599) (CVE-2022-26904) (CVE-2022-24521)
PATCH-333892022-04 Cumulative Update for Windows 10 Version 20H2 for x64-based Systems (KB5012599) (CVE-2022-26904) (CVE-2022-24521)
PATCH-333912022-04 Cumulative Update for Windows 10 Version 21H2 for x64-based Systems (KB5012599) (CVE-2022-26904) (CVE-2022-24521)
PATCH-333922022-04 Cumulative Update for Windows 10 Version 21H2 for x86-based Systems (KB5012599) (CVE-2022-26904) (CVE-2022-24521)
PATCH-333932022-04 Cumulative Update for Microsoft server operating system version 21H2 for x64-based Systems (KB5012604) (CVE-2022-26904) (CVE-2022-24521)
PATCH-333822022-04 Cumulative Update for Windows Server 2019 for x64-based Systems (KB5012647) (CVE-2022-26904) (CVE-2022-24521)
PATCH-333832022-04 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB5012647) (CVE-2022-26904) (CVE-2022-24521)
PATCH-333842022-04 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB5012647) (CVE-2022-26904) (CVE-2022-24521)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234