CVE-2022-3786

OpenSSL: CVE-2022-3786 X.509 certificate verification buffer overrun

Published
November 2, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Why is this OpenSSL Software Foundation CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in OpenSSL Software which is consumed by the Microsoft products listed in the Security Updates table and are known to be affected. It is being documented in the Security Update Guide to announce that the latest builds of these products are no longer vulnerable. Please see Security Update Guide Supports CVEs Assigned by Industry Partners for more information.

Where can I find further guidance for this OpenSSL vulnerability? For more information and guidance see Awareness and guidance related to OpenSSL 3.0 - 3.0.6 risk (CVE-2022-3786 and CVE-2202-3602).

🎯 Affected products3

  • Azure SDK for C++
  • Microsoft Azure Kubernetes Service
  • vcpkg

✅ Remediation

KBRelease Notes (Security Update) — fixed build 2022.11.02 KBRelease Notes (Security Update)

🔗 References (3)