CVE-2022-33644HighCVSS 7.0

Xbox Live Save Service Elevation of Privilege Vulnerability

Published
July 12, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The user must be authenticated into an Xbox Live account to be able to exploit this vulnerability.

🎯 Affected products8

  • Windows 10 Version 20H2 for 32-bit Systems
  • Windows 10 Version 20H2 for ARM64-based Systems
  • Windows 10 Version 21H1 for 32-bit Systems
  • Windows 10 Version 21H1 for ARM64-based Systems
  • Windows 10 Version 21H1 for x64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems

✅ Remediation

KB5015807 (Security Update) — fixed build 10.0.19042.1826 KB5015807 (Security Update) — fixed build 10.0.19043.1826 KB5015807 (Security Update) — fixed build 10.0.19044.1826

🔗 References (3)