CVE-2022-37972: Microsoft Endpoint Configuration Manager Spoofing Vulnerability

Overview

Severity
High (CVSS 7.5)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C
Category
Spoofing
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Publicly Disclosed
Yes
Patch Tuesday
2022-Sep
Released
2022-09-20
Last Updated
2022-11-29
EPSS Score
10.36% (percentile: 93.2%)

FAQ

How do I get the update? The update – KB 15498768 – will be listed in the Updates and Servicing node of the Configuration Manager console for customers running Microsoft Endpoint Configuration Manager, versions 2103 – 2207. Environments using versions of Configuration Manager current branch prior to 2103 are encouraged to update to a later supported version. Administrators can also disable use of automatic and manual client push installation methods to remove the risk of exposure to this issue. Refer to Support for Configuration Manager current branch versions. What is Microsoft Endpoint Configuration Manager? Microsoft Endpoint Configuration Manager is an on-premises management solution to manage desktops, servers, and laptops that are on your network or are internet-based. You can cloud-enable it to integrate with Intune, Azure Active Directory (AD), Microsoft Defender for Endpoint, and other cloud services. Use Configuration Manager to deploy apps, software updates, and operating systems. You can also monitor compliance, query and act on clients in real time, and much more. For more information see - What is Configuration Manager?.

Affected Products (1)

System Center

  • Microsoft Endpoint Configuration Manager

Security Updates (1)

Acknowledgments

<a href="https://twitter.com/techbrandon">Brandon Colley</a> with <a href="https://www.trimarcsecurity.com/">Trimarc Security</a>

Revision History

  • 2022-09-20: Information published.
  • 2022-11-08: Updated one or more CVSS scores for the affected products. This is an informational change only.
  • 2022-11-29: Updated one or more CVSS scores for the affected products. This is an informational change only.