CVE-2022-37975
About
Windows Group Policy Elevation of Privilege Vulnerability
Rainforest analyst review
This is a Windows Group Policy elevation-of-privilege bug: an attacker who already has a foothold with some privileges on the machine can abuse Group Policy handling to climb higher, up to full compromise of the host. The description is terse, but the shape is clear from the metrics, local, low-privileged starting point, no user interaction, leading to high impact on all three of confidentiality, integrity, and availability.
Privilege-escalation bugs are second-stage tools, not front doors. Nobody scans the internet for this; it matters once an attacker is already on the box via phishing, a stolen credential, or another exploit, and needs to become SYSTEM to disable defenses and move laterally. That makes it a staple of real intrusion chains even though it does nothing for an attacker who isn't already inside.
For a Patch Tuesday item like this, our job is coverage and cadence: confirm the October rollup is actually landing across the Windows estate, including the older Server 2008 and Windows 7 assets that tend to lag. We would rank it as an important part of defense-in-depth rather than an emergency, and lean on endpoint detection to catch the post-compromise activity that would precede any attempt to use it.
References
Related CVEs
No related CVEs.
Frequently asked questions
What is CVE-2022-37975?
Windows Group Policy Elevation of Privilege Vulnerability
How severe is CVE-2022-37975?
CVE-2022-37975 carries a CVSS 3.1 base score of 8.8, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 89 out of 100, in the critical band.
How is CVE-2022-37975 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2022-37975?
Public advisories list the following as affected: windows 10, windows 11, windows 7, windows 8.1, windows rt 8.1, windows server 2008, +4. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2022-37975?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
