CVE-2022-38014HighCVSS 7.0

Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability

Published
November 8, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition.

🎯 Affected products2

  • Azure EFLOW
  • Windows Subsystem for Linux (WSL2)

✅ Remediation

KBRelease Notes (Security Update) — fixed build 5.15.62.1 KBRelease Notes (Security Update) — fixed build 1.4.2.12122 LTS

🔗 References (4)