CVE-2022-37966: Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
Published Nov 8, 2022
·Updated
Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
Affected Software
31 affected components
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012
Microsoft Windows Server 2008
Microsoft Windows Server 2008
Microsoft Windows Server 2008
Microsoft Windows Server 2008
Microsoft Windows Server 2016
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Microsoft Windows Server 2022
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Fedoraproject Fedora=36
Fedoraproject Fedora=37
NetApp Management Services For Element Software
NetApp Management Services For Netapp Hci
Samba Samba<4.15.13
Samba Samba>=4.16.0<4.16.8
Samba Samba>=4.17.0<4.17.4
Samba Samba>4.15.13
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2008 R2
Remediation
Event History
Nov 8, 2022
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Nov 9, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-37966?
CVE-2022-37966 is a Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability.
2
How severe is CVE-2022-37966?
CVE-2022-37966 has a severity value of 8.1, which is considered critical.
3
Which software is affected by CVE-2022-37966?
The software affected by CVE-2022-37966 includes Microsoft Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016, 2019, and 2022, as well as Fedora, Netapp Management Services, and Samba.
4
How can I fix CVE-2022-37966 on Windows Server 2008?
To fix CVE-2022-37966 on Windows Server 2008, you can apply the security patches provided by Microsoft. Please refer to the Microsoft support page for more information.
5
Where can I find more information about CVE-2022-37966?
You can find more information about CVE-2022-37966 on the Microsoft Security Response Center website and the Gentoo Security Advisory.