CVE-2022-23266: Microsoft Defender for IoT Elevation of Privilege Vulnerability
Published Mar 8, 2022
·Updated
Microsoft Defender for IoT Elevation of Privilege Vulnerability
Affected Software
2 affected componentsFixes available
Microsoft Defender for IoT<22.1.2
Microsoft Defender for IoT
Event History
Mar 8, 2022
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:00 AM
Description
Mar 9, 2022
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-23266?
CVE-2022-23266 is a vulnerability in Microsoft Defender for IoT that allows an attacker to elevate their privileges.
2
How severe is CVE-2022-23266?
CVE-2022-23266 has a severity rating of 7.8 (High).
3
Which software is affected by CVE-2022-23266?
Microsoft Defender for IoT versions up to and excluding 22.1.2 are affected by CVE-2022-23266.
4
How can I fix CVE-2022-23266?
To fix CVE-2022-23266, update your Microsoft Defender for IoT software to a version higher than 22.1.2.
5
Where can I find more information about CVE-2022-23266?
You can find more information about CVE-2022-23266 on the Microsoft Security Response Center website: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23266