CVE-2022-37980HighCVSS 7.8
Windows DHCP Client Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? An authenticated attacker could leverage a specially crafted RPC call to the DHCP service to exploit this vulnerability.
What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
🎯 Affected products14
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows 10 Version 21H1 for 32-bit Systems
- Windows 10 Version 21H1 for ARM64-based Systems
- Windows 10 Version 21H1 for x64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
✅ Remediation
KB5018410 (Security Update) — fixed build 10.0.19043.2130 KB5018421 (Security Update) — fixed build 10.0.20348.1129 KB5018410 (Security Update) — fixed build 10.0.19042.2130 KB5018418 (Security Update) — fixed build 10.0.22000.1098 KB5018410 (Security Update) — fixed build 10.0.19044.2130 KB5018427 (Security Update) — fixed build 10.0.22621.674
🔗 References (9)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37980
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5018410
- referencehttps://support.microsoft.com/help/5018410
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5018421
- referencehttps://support.microsoft.com/help/5018421
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5018418
- referencehttps://support.microsoft.com/help/5018418
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5018427
- referencehttps://support.microsoft.com/help/5018427