# CVE-2022-50238

## Summary

- **CVE ID:** CVE-2022-50238
- **Severity:** HIGH
- **CVSS Score:** 7.4 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-820
- **Published:** Sep 8, 2025
- **Last Modified:** Mar 13, 2026

## Description

The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online list have been excluded from the on-endpoint blocklist longer than the expected periodic monthly Windows updates. It is possible to fully synchronize the driver blocklist using WDAC policies. NOTE: The vendor explains that Windows Update provides a smaller, compatibility-focused driver blocklist for general users, while the full XML list is available for advanced users and organizations to customize at the risk of usability issues.

## Affected Products

- Microsoft — Windows (10)

## References

- [CNA](https://github.com/wdormann/applywdac)
- [CNA](https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/design/microsoft-recommended-driver-block-rules)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.04%
- **EPSS Percentile:** 11.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._