CVE-2022-41120 is an Elevation of Privilege vulnerability affecting Microsoft Windows System Monitor (Sysmon). With a CVSS score of 7.8 (High), this vulnerability allows a local attacker to gain high confidentiality, integrity, and availability impacts with low attack complexity. While not currently listed on CISA KEV, it was addressed in Microsoft's November 2022 Patch Tuesday, and there is no public exploit code available or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:windows_sysmon:-:*:*:*:*:*:*:* | ||
>= 1.0, < 14.11CPE match | cpe:2.3:a:microsoft:windows_sysmon:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.