CVE detail
CVE-2022-37967
Windows Kerberos Elevation of Privilege Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
We’re halfway through 2023 already and moving into our seventh Patch Tuesday of the year next week. There’s been a lot of activity with Microsoft this month which may impact updates we’ll see. But first taking a quick look back at June, we had a fairly standard set of releases with 32 CVEs fixed in Windows 11 and 36 fixed in Windows 10. Although I call out the desktops for simplicity, always keep in mind … More →
newswww.helpnetsecurity.comJul 7, 2023, 9:07 AM- Samba addressed multiple high-severity vulnerabilitiesSecurity Affairs
Samba released updates to address multiple vulnerabilities that can be exploited to take control of impacted systems. Samba released updates to address multiple vulnerabilities, tracked as CVE-2022-38023, CVE-2022-37966, CVE-2022-37967, and CVE-2022-45141, that can be exploited to take control of impacted systems. On December 15, 2022, Samba announced the 4.17.4, 4.16.8 and 4.15.13 security releases to address […]
newssecurityaffairs.comDec 17, 2022, 5:29 PM - December 2022 Patch Tuesday forecast: Fine-tuning the connectivityHelp Net Security
Microsoft wrapped up a lot of ‘loose ends’ last month with their November set of updates, but there is still some work to do before the end-of-year holiday season. The ProxyNotShell vulnerabilities were finally fixed, and we saw some improvements in the changes made to communication and authentication exchanges. However, there is some ‘fine tuning’ still needed based on the chatter from patch forums and articles in the news. Microsoft began introducing security hardening in … More →
newswww.helpnetsecurity.comDec 9, 2022, 6:28 AM Do you recall when you last reset your Kerberos password ? Hopefully that was not the last time I suggested you change it, back in April of 2021, when I urged you to do a regular reset of the KRBTGT account password. If you’ve followed my advice, you are already one step ahead of the […]
newswww.csoonline.comNov 23, 2022, 10:00 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-38023CVSS 8.1 · High
Netlogon RPC Elevation of Privilege Vulnerability
5 mentions - CVE-2022-37966CVSS 8.1 · High
Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
7 mentions - CVE-2023-50387CVSS 7.5 · High
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more…
- CVE-2020-1472CVSS 5.5 · Medium
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Proto…
KEV listedPublic PoC observed82 mentions - CVE-2026-20940CVSS 7.8 · High
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-20936CVSS 4.3 · Medium
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.