Back to overview

CVE-2022-37968

CRITICAL
10.0
CVSS 3.1

Metadata

CVE ID
CVE-2022-37968
State
PUBLISHED
Assigner
microsoft
Reserved
2022-08-08 00:00 UTC
Published
2022-10-11 00:00 UTC
Last updated
2025-01-02 21:27 UTC
Vendor / Product
Microsoft / Azure Arc-enabled Kubernetes cluster 1.8.11
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected products (5)
VendorProductPlatformVersions
Microsoft Azure Arc-enabled Kubernetes cluster 1.5.8 Unknown 1.0.0 < 1.5.8
Microsoft Azure Arc-enabled Kubernetes cluster 1.6.19 Unknown 1.0.0 < 1.6.19
Microsoft Azure Arc-enabled Kubernetes cluster 1.7.18 Unknown 1.0.0 < 1.7.18
Microsoft Azure Arc-enabled Kubernetes cluster 1.8.11 Unknown 1.0.0 < 1.8.11
Microsoft Azure Stack Edge Unknown 2.2.0 < 2.2.2088.5593
Weakness (CWE)
CWESourceDescription
cna Elevation of Privilege
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
References (1)
Back to overview