๐Ÿ” CVE Alert

CVE-2022-37967

HIGH 7.2

Windows Kerberos Elevation of Privilege Vulnerability

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

Windows Kerberos Elevation of Privilege Vulnerability

Vendor microsoft
Product windows server 2019
Ecosystems
Industries
TechnologyEnterprise
Published Nov 9, 2022
Last Updated Jan 2, 2025
Stay Ahead of the Next One

Get instant alerts for microsoft windows server 2019

Be the first to know when new high vulnerabilities affecting microsoft windows server 2019 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Microsoft / Windows Server 2019
10.0.17763.0 < 10.0.17763.4974
Microsoft / Windows Server 2019 (Server Core installation)
10.0.17763.0 < 10.0.17763.4974
Microsoft / Windows Server 2022
10.0.20348.0 < 10.0.20348.2031
Microsoft / Windows Server 2016
10.0.14393.0 < 10.0.14393.6351
Microsoft / Windows Server 2016 (Server Core installation)
10.0.14393.0 < 10.0.14393.6351
Microsoft / Windows Server 2008 Service Pack 2
6.0.6003.0 < 6.0.6003.22317
Microsoft / Windows Server 2008 Service Pack 2 (Server Core installation)
6.0.6003.0 < 6.0.6003.22317
Microsoft / Windows Server 2008 Service Pack 2
6.0.6003.0 < 6.0.6003.22317
Microsoft / Windows Server 2008 R2 Service Pack 1
6.1.7601.0 < 6.1.7601.26769
Microsoft / Windows Server 2008 R2 Service Pack 1 (Server Core installation)
6.1.7601.0 < 6.1.7601.26769
Microsoft / Windows Server 2012
6.2.9200.0 < 6.2.9200.24523
Microsoft / Windows Server 2012 (Server Core installation)
6.2.9200.0 < 6.2.9200.24523
Microsoft / Windows Server 2012 R2
6.3.9600.0 < 6.3.9600.21620
Microsoft / Windows Server 2012 R2 (Server Core installation)
6.3.9600.0 < 6.3.9600.21620

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
msrc.microsoft.com: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37967 security.gentoo.org: https://security.gentoo.org/glsa/202309-06