QID 92020
QID 92020: Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability (November 2022)
System Monitor (Sysmon) is a Windows system service and device driver that, once installed on a system, remains resident across system reboots to monitor and log system activity to the Windows event log
Affected Software
Sysmon prior to version 14.11.0.0
QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Sysmon.exe
Successful exploit could lead to elevation of privileges
Solution
Customers are advised to refer to CVE-2022-41120 for more details pertaining to this vulnerability.
Vendor References
- CVE-2022-41120 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41120
CVEs related to QID 92020
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-41120 |
|