CVE-2022-29799

MEDIUM LAB

Microsoft Windows Defender For Endpoint - Path Traversal

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2022-29799. PoCs published by joshuavanderpoll, pansyhebephrenic23.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2022-29799 and CVE-2022-29800, which involve a path traversal vulnerability and a symlink TOCTOU race condition in networkd-dispatcher. The exploit allows an unprivileged local user to escalate privileges to root by manipulating the OperationalState property via D-Bus and exploiting a race condition in script execution.

Description

A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base directory.

Exploits (3)

nomisec WORKING POC 1 stars
by joshuavanderpoll · poc
https://github.com/joshuavanderpoll/NimbusPWN-CVE-2022-29799-29800

This repository contains a functional exploit for CVE-2022-29799 and CVE-2022-29800, which involve a path traversal vulnerability and a symlink TOCTOU race condition in networkd-dispatcher. The exploit allows an unprivileged local user to escalate privileges to root by manipulating the OperationalState property via D-Bus and exploiting a race condition in script execution.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: networkd-dispatcher < 2.1
No auth needed
Prerequisites: Local access to the system · D-Bus system bus access · networkd-dispatcher version < 2.1
mistral-large-3 · analyzed Jun 18, 2026 Full analysis →
nomisec SUSPICIOUS
by pansyhebephrenic23 · poc
https://github.com/pansyhebephrenic23/pansyhebephrenic23.github.io

The repository lacks actual exploit code and instead directs users to download an executable from an external release page. The README is vague, lacks technical details about the vulnerability, and focuses on marketing language.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: networkd-dispatcher (versions affected by CVE-2022-29799 and CVE-2022-29800)
No auth needed
Prerequisites: Windows system · standard user account
mistral-large-3 · analyzed Jun 24, 2026 Full analysis →
nomisec WORKING POC
by pansyhebephrenic23 · poc
https://github.com/pansyhebephrenic23/NimbusPWN-CVE-2022-29799-29800

This repository contains a functional exploit for CVE-2022-29799 and CVE-2022-29800, which involve a path traversal and symlink TOCTOU vulnerability in networkd-dispatcher. The exploit allows an unprivileged local user to escalate privileges to root by manipulating the OperationalState via D-Bus and exploiting a race condition in script execution.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: networkd-dispatcher < 2.1
No auth needed
Prerequisites: Local access to the system · networkd-dispatcher version < 2.1 · D-Bus access
mistral-large-3 · analyzed Jun 24, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.1167
EPSS Percentile 95.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
microsoft/windows_defender_for_endpoint
Published Sep 21, 2022
Tracked Since Feb 18, 2026