#VU69094 Permissions, Privileges, and Access Controls in Windows and Windows Server - CVE-2022-37966
Published: November 8, 2022 / Updated: December 15, 2022
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in Windows Kerberos RC4-HMAC. A remote attacker can conduct a man-in-middle (MiTM) attack, which leads to security restrictions bypass and privilege escalation.