CVE-2022-21882 is a Win32k Elevation of Privilege vulnerability affecting multiple versions of Microsoft Windows 10, 11, and Server. It carries a high CVSS score of 7.8, indicating a significant risk due to its ability to allow a local, low-privileged attacker to gain elevated privileges with high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and public exploit modules, such as a Metasploit module, are available. The high EPSS score and extensive community discussion, including detailed analyses and media coverage, underscore its critical nature and widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.2452CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.2452CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.18363.2037CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1909:*:*:*:*:*:*:*:* | ||
< 10.0.19042.1466CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_20h2:*:*:*:*:*:*:*:* | ||
< 10.0.19043.1466CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.