CVE-2022-2188
Last modified
CVE-2022-2188 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker. . EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Data Exchange Layer | < 6.0.0.280 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2188?
How severe is CVE-2022-2188?
How do I fix CVE-2022-2188?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-21874Windows Security Center API Remote Code Execution Vulnerabil…9.8
- CVE-2022-21875Windows Storage Elevation of Privilege Vulnerability7.8
- CVE-2022-21876Win32k Information Disclosure Vulnerability5.5
- CVE-2022-21877Storage Spaces Controller Information Disclosure Vulnerabili…5.5
- CVE-2022-21878Windows Geolocation Service Remote Code Execution Vulnerabil…7.8
- CVE-2022-21879Windows Kernel Elevation of Privilege Vulnerability7.8
- CVE-2022-21880Windows GDI+ Information Disclosure Vulnerability7.5
- CVE-2022-21881Windows Kernel Elevation of Privilege Vulnerability7
- CVE-2022-21882Win32k Elevation of Privilege Vulnerability7.8
- CVE-2022-21883Windows Internet Key Exchange (IKE) Extension Denial of Serv…7.5
- CVE-2022-21884Local Security Authority Subsystem Service Elevation of Priv…7.8
- CVE-2022-21885Windows Remote Access Connection Manager Elevation of Privil…7.8
Are you affected by CVE-2022-2188?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
