Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.821272
Category:Windows : Microsoft Bulletins
Title:Microsoft Windows Multiple Vulnerabilities (KB5015807)
Summary:This host is missing an important security; update according to Microsoft KB5015807
Description:Summary:
This host is missing an important security
update according to Microsoft KB5015807

Vulnerability Insight:
Multiple flaws exist due to:

- A security bypass vulnerability in BitLocker.

- An insufficiently protected credentials vulnerability might leak
authentication or cookie header data.

- An elevation of privilege vulnerability in Windows CSRSS.

For more information about the vulnerabilities refer to Reference links.

Vulnerability Impact:
Successful exploitation will allow an attacker
to elevate privileges, execute arbitrary commands, disclose information,
bypass security restrictions, conduct tampering and DoS attacks on an affected
system.

Affected Software/OS:
- Microsoft Windows 10 Version 20H2 for 32-bit Systems

- Microsoft Windows 10 Version 20H2 for x64-based Systems

- Microsoft Windows 10 Version 21H1 for 32-bit Systems

- Microsoft Windows 10 Version 21H1 for x64-based Systems

- Microsoft Windows 10 Version 21H2 for 32-bit Systems

- Microsoft Windows 10 Version 21H2 for x64-based Systems

Solution:
The vendor has released updates. Please see
the references for more information.

CVSS Score:
8.5

CVSS Vector:
AV:N/AC:M/Au:S/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-21845
Windows Kernel Information Disclosure Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21845
Common Vulnerability Exposure (CVE) ID: CVE-2022-22022
Windows Print Spooler Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22022
Common Vulnerability Exposure (CVE) ID: CVE-2022-22023
Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22023
Common Vulnerability Exposure (CVE) ID: CVE-2022-22024
Windows Fax Service Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22024
Common Vulnerability Exposure (CVE) ID: CVE-2022-22025
Windows Internet Information Services Cachuri Module Denial of Service Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22025
Common Vulnerability Exposure (CVE) ID: CVE-2022-22026
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22026
Common Vulnerability Exposure (CVE) ID: CVE-2022-22027
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22027
Common Vulnerability Exposure (CVE) ID: CVE-2022-22028
Windows Network File System Information Disclosure Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22028
Common Vulnerability Exposure (CVE) ID: CVE-2022-22029
Windows Network File System Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22029
Common Vulnerability Exposure (CVE) ID: CVE-2022-22031
Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22031
Common Vulnerability Exposure (CVE) ID: CVE-2022-22034
Windows Graphics Component Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22034
Common Vulnerability Exposure (CVE) ID: CVE-2022-22036
Performance Counters for Windows Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22036
Common Vulnerability Exposure (CVE) ID: CVE-2022-22037
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22037
Common Vulnerability Exposure (CVE) ID: CVE-2022-22038
Remote Procedure Call Runtime Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22038
Common Vulnerability Exposure (CVE) ID: CVE-2022-22039
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22039
Common Vulnerability Exposure (CVE) ID: CVE-2022-22040
Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22040
Common Vulnerability Exposure (CVE) ID: CVE-2022-22041
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22041
Common Vulnerability Exposure (CVE) ID: CVE-2022-22042
Windows Hyper-V Information Disclosure Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22042
Common Vulnerability Exposure (CVE) ID: CVE-2022-22043
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22043
Common Vulnerability Exposure (CVE) ID: CVE-2022-22045
Windows.Devices.Picker.dll Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22045
Common Vulnerability Exposure (CVE) ID: CVE-2022-22047
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22047
Common Vulnerability Exposure (CVE) ID: CVE-2022-22048
BitLocker Security Feature Bypass Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22048
Common Vulnerability Exposure (CVE) ID: CVE-2022-22049
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22049
Common Vulnerability Exposure (CVE) ID: CVE-2022-22050
Windows Fax Service Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22050
Common Vulnerability Exposure (CVE) ID: CVE-2022-22711
Windows BitLocker Information Disclosure Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22711
Common Vulnerability Exposure (CVE) ID: CVE-2022-27776
Debian Security Information: DSA-5197 (Google Search)
https://www.debian.org/security/2022/dsa-5197
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DKKOQXPYLMBSEVDHFS32BPBR3ZQJKY5B/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7N5ZBWLNNPZKFK7Q4KEHGCJ2YELQEUJP/
https://security.gentoo.org/glsa/202212-01
https://hackerone.com/reports/1547048
https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-30202
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30202
Common Vulnerability Exposure (CVE) ID: CVE-2022-30203
Windows Boot Manager Security Feature Bypass Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30203
Common Vulnerability Exposure (CVE) ID: CVE-2022-30205
Windows Group Policy Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30205
Common Vulnerability Exposure (CVE) ID: CVE-2022-30206
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30206
Common Vulnerability Exposure (CVE) ID: CVE-2022-30208
Windows Security Account Manager (SAM) Denial of Service Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30208
Common Vulnerability Exposure (CVE) ID: CVE-2022-30209
Windows IIS Server Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30209
Common Vulnerability Exposure (CVE) ID: CVE-2022-30211
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30211
Common Vulnerability Exposure (CVE) ID: CVE-2022-30212
Windows Connected Devices Platform Service Information Disclosure Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30212
Common Vulnerability Exposure (CVE) ID: CVE-2022-30213
Windows GDI+ Information Disclosure Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30213
Common Vulnerability Exposure (CVE) ID: CVE-2022-30214
Windows DNS Server Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30214
Common Vulnerability Exposure (CVE) ID: CVE-2022-30215
Active Directory Federation Services Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30215
Common Vulnerability Exposure (CVE) ID: CVE-2022-30216
Windows Server Service Tampering Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30216
Common Vulnerability Exposure (CVE) ID: CVE-2022-30220
Windows Common Log File System Driver Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30220
Common Vulnerability Exposure (CVE) ID: CVE-2022-30221
Windows Graphics Component Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30221
Common Vulnerability Exposure (CVE) ID: CVE-2022-30222
Windows Shell Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30222
Common Vulnerability Exposure (CVE) ID: CVE-2022-30223
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30223
Common Vulnerability Exposure (CVE) ID: CVE-2022-30224
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30224
Common Vulnerability Exposure (CVE) ID: CVE-2022-30225
Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30225
Common Vulnerability Exposure (CVE) ID: CVE-2022-30226
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30226
Common Vulnerability Exposure (CVE) ID: CVE-2022-33644
Xbox Live Save Service Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-33644
CopyrightCopyright (C) 2022 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.