CVE-2022-37972: Microsoft Endpoint Configuration Manager Spoofing Vulnerability
Published Sep 20, 2022
·Updated
Microsoft Endpoint Configuration Manager Spoofing Vulnerability.
Affected Software
2 affected componentsFixes available
Microsoft Endpoint Configuration Manager>=2103<=2207
Microsoft Endpoint Configuration Manager
Remediation
Event History
Sep 20, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-37972?
CVE-2022-37972 is categorized as a spoofing vulnerability, which can potentially allow attackers to impersonate valid users.
2
How do I fix CVE-2022-37972?
To fix CVE-2022-37972, ensure that you apply the latest available patches from Microsoft for the Endpoint Configuration Manager.
3
What versions are affected by CVE-2022-37972?
CVE-2022-37972 affects Microsoft Endpoint Configuration Manager versions between 2103 and 2207.
4
What are the potential impacts of CVE-2022-37972?
If exploited, CVE-2022-37972 may allow an attacker to present themselves as a legitimate user within the system.
5
Is there a workaround for CVE-2022-37972?
There are no known workarounds for CVE-2022-37972, so applying the appropriate updates is highly recommended.