CVE-2022-37966

Summary

Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability

Affected Software

VendorProductVersion RangeStatus
MicrosoftWindows Server 2008 Service Pack 2-affected
MicrosoftWindows Server 2008 R2 Service Pack 1-affected
MicrosoftWindows Server 2008 R2 Service Pack 1 (Server Core installation)-affected
MicrosoftWindows Server 2008 Service Pack 2-affected
MicrosoftWindows Server 2008 Service Pack 2 (Server Core installation)-affected
MicrosoftWindows Server 2012-affected
MicrosoftWindows Server 2012 (Server Core installation)-affected
MicrosoftWindows Server 2012 R2-affected
MicrosoftWindows Server 2012 R2 (Server Core installation)-affected
MicrosoftWindows Server 2016-affected
MicrosoftWindows Server 2016 (Server Core installation)-affected
MicrosoftWindows Server 2019-affected
MicrosoftWindows Server 2019 (Server Core installation)-affected
MicrosoftWindows Server 2022-affected

Weaknesses

  • Elevation of Privilege

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References