CVE-2022-21971 is a Windows Runtime Remote Code Execution Vulnerability affecting multiple versions of Windows 10, Windows 11, and Windows Server. This vulnerability carries a high CVSS score of 7.8, indicating a significant risk, and allows for complete compromise of confidentiality, integrity, and availability, typically requiring user interaction for exploitation. Critically, this vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered substantial community discussion and media coverage. Despite active exploitation, no public exploit code is currently available on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.2565CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:* | ||
< 10.0.18363.2094CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1909:*:*:*:*:*:*:*:* | ||
< 10.0.19042.1526CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_20h2:*:*:*:*:*:*:*:* | ||
< 10.0.19043.1526CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:*:* | ||
< 10.0.19044.1526CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.