CVE-2022-29800

MEDIUM

Microsoft Windows Defender For Endpoint - TOCTOU Race Condition

Title source: rule
STIX 2.1

Description

A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.

Exploits (1)

nomisec WORKING POC
by ngtuonghung · poc
https://github.com/ngtuonghung/nimbuspwn-CVE-2022-29800-CVE-2022-29799

Scores

CVSS v3 4.7
EPSS 0.0009
EPSS Percentile 25.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-367
Status published
Products (1)
microsoft/windows_defender_for_endpoint
Published Sep 21, 2022
Tracked Since Feb 18, 2026