The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online list have been excluded from the on-endpoint blocklist longer than the expected periodic monthly Windows updates. It is possible to fully synchronize the driver blocklist using WDAC policies. NOTE: The vendor explains that Windows Update provides a smaller, compatibility-focused driver blocklist for general users, while the full XML list is available for advanced users and organizations to customize at the risk of usability issues.
References
Configurations
No configuration.
History
17 Oct 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-820 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.4 |
08 Sep 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-08 15:15
Updated : 2025-10-17 19:15
NVD link : CVE-2022-50238
Mitre link : CVE-2022-50238
CVE.ORG link : CVE-2022-50238
JSON object : View
Products Affected
No product.
CWE
CWE-820
Missing Synchronization
