EXPOSURES › CVE-2022-37969
CVE-2022-37969
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 90/100
exploited-in-wildunpatched
Microsoft Windows CLFS Driver allows unauthorized escalation of privileges
A critical Windows driver vulnerability was actively exploited, enabling attackers to gain elevated access without authentication.
Shame score — Active exploitation in the wild without a disclosed patch, posing a severe risk to DIB systems.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
AFFECTED FEDRAMP PRODUCTS · 4
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |