Lucene search

K
kasperskyKaspersky LabKLA62829
HistoryJan 09, 2024 - 12:00 a.m.

KLA62829 ACE vulnerability in Microsoft Mariner

2024-01-0900:00:00
Kaspersky Lab
threats.kaspersky.com
15
microsoft mariner
array-bounds overflow
arbitrary code
public exploits
cbl mariner 2.0

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

8.4

Confidence

High

EPSS

0.003

Percentile

65.5%

A array-bounds overflow vulnerability was found in Microsoft Mariner. Malicious users can exploit this vulnerability to execute arbitrary code.

Original advisories

CVE-2022-35737

Exploitation

Public exploits exist for this vulnerability.

Related products

CBL-Mariner-2.0

CVE list

CVE-2022-35737 unknown

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • CBL Mariner 2.0

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

8.4

Confidence

High

EPSS

0.003

Percentile

65.5%