CVE-2022-21884 is a Local Security Authority Subsystem Service (LSASS) Elevation of Privilege vulnerability affecting multiple versions of Microsoft Windows Server. With a CVSS score of 7.8 (High), it allows a local attacker with low privileges to achieve high impact on confidentiality, integrity, and availability. While Microsoft patched this vulnerability in January 2022, there is currently no public exploit code available, nor is it listed in CISA's Known Exploited Vulnerabilities catalog. Despite limited community discussion and media coverage, its high severity warrants prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server:20h2:*:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server:2022:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.