CVE-2022-50238
The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online list have been excluded from the on-endpoint blocklist longer than the expected periodic monthly Windows updates. It is possible to fully synchronize the driver blocklist using WDAC policies. NOTE: The vendor explains that Windows Update provides a smaller, compatibility-focused driver blocklist for general users, while the full XML list is available for advanced users and organizations to customize at the risk of usability issues.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.04%
- CWE
- CWE-820
- Published
- 2025-09-08
- Last modified
- 2026-03-13
Affected products
- Microsoft Windows
Weakness type
Related vulnerabilities
- CVE-2026-70637 — LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c
- CVE-2026-57029 — Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash
- CVE-2026-44318 — free5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions
- CVE-2026-22163 — GPU DDK - Unsafe writing of MMU PT entries on systems with 32-bit host CPU
- CVE-2025-49751 — Windows Hyper-V Denial of Service Vulnerability
- CVE-2025-47999 — Windows Hyper-V Denial of Service Vulnerability
- CVE-2025-47154 — LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list...
- CVE-2025-1445 — A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the...