CVE-2022-35737High
MITRE: CVE-2022-35737 SQLite allows an array-bounds overflow
🔗 CVE IDs covered (1)
📋 Description
Why is the MITRE Corporation the assigning CNA (CVE Numbering Authority)? CVE-2022-35737 is regarding a vulnerability in SQLite. MITRE assigned this CVE number on behalf of the SQLite organization. Microsoft has included the updated library in Windows that addresses this vulnerability.
🎯 Affected products17
- CBL Mariner 1.0 ARM
- CBL Mariner 1.0 x64
- CBL Mariner 2.0 ARM
- CBL Mariner 2.0 x64
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 Version 22H2 for 32-bit Systems
- Windows 10 Version 22H2 for ARM64-based Systems
- Windows 10 Version 22H2 for x64-based Systems
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
✅ Remediation
KBsqlite (CBL-Mariner) — fixed build 3.34.1-2 KBsqlite (CBL-Mariner) — fixed build 3.39.2-1 KB5034127 (Security Update) — fixed build 10.0.17763.5329 KB5034129 (Security Update) — fixed build 10.0.20348.2227 KB5034122 (Security Update) — fixed build 10.0.19044.3930 KB5034122 (Security Update) — fixed build 10.0.19045.3930
🔗 References (8)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-35737
- referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-35737
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5034127
- referencehttps://support.microsoft.com/help/5034127
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5034129
- referencehttps://support.microsoft.com/help/5034129
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5034122
- referencehttps://support.microsoft.com/help/5034122