Security features bypass in Microsoft Windows and Windows Server - CVE-2022-22048

 

Security features bypass in Microsoft Windows and Windows Server - CVE-2022-22048

Published: July 12, 2022


Vulnerability identifier: #VU65216
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22048
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass authentication process.

The vulnerability exists due to security feature bypass issue in BitLocker. An attacker with physical access can bypass the BitLocker Device Encryption feature on the system storage device and gain access to encrypted data.


Affected software

Microsoft Windows
Windows Server
Solutions Enabler
Unisphere 360
Unisphere for PowerMax
Unisphere for PowerMax Virtual Appliance
eVASA Provider Virtual Appliance
VASA Provider Standalone
Solutions Enabler Virtual Appliance

How to mitigate CVE-2022-22048

Install updates from vendor's website.

Solutions Enabler - update to 9.2.3.5
Solutions Enabler Virtual Appliance - update to 9.2.3.5
Unisphere 360 - update to 9.2.3.8
Unisphere for PowerMax - update to 9.2.3.20
Unisphere for PowerMax Virtual Appliance - update to 9.2.3.20
eVASA Provider Virtual Appliance - update to 9.2.4.11
VASA Provider Standalone - update to 9.2.4.21

External References

Related Security Bulletins