7.8 High
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.8 High
AI Score
Confidence
High
0.002 Low
EPSS
Percentile
62.1%
Multiple vulnerabilities were found in Microsoft Developer Tools. Malicious users can exploit these vulnerabilities to gain privileges, obtain sensitive information, execute arbitrary code.
Below is a complete list of vulnerabilities:
Public exploits exist for this vulnerability.
CVE-2022-41120 critical
CVE-2022-41064 high
CVE-2022-41119 critical
CVE-2022-39253 high
Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)
Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.
Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.
Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.
Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.
support.microsoft.com/kb/5019964
support.microsoft.com/kb/5019970
support.microsoft.com/kb/5020614
support.microsoft.com/kb/5020622
support.microsoft.com/kb/5020678
support.microsoft.com/kb/5020679
support.microsoft.com/kb/5020680
support.microsoft.com/kb/5020681
support.microsoft.com/kb/5020685
support.microsoft.com/kb/5020686
support.microsoft.com/kb/5020687
support.microsoft.com/kb/5020688
support.microsoft.com/kb/5020689
support.microsoft.com/kb/5020690
support.microsoft.com/kb/5020691
support.microsoft.com/kb/5020692
support.microsoft.com/kb/5020694
support.microsoft.com/kb/5020695
support.microsoft.com/kb/5020801
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-39253
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41064
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41119
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41120
statistics.securelist.com/
threats.kaspersky.com/en/product/Microsoft-.NET-Framework/
threats.kaspersky.com/en/product/Microsoft-Visual-Studio/
threats.kaspersky.com/en/product/Microsoft-Windows/
7.8 High
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.8 High
AI Score
Confidence
High
0.002 Low
EPSS
Percentile
62.1%