CVE-2022-22003 is a Microsoft Office Graphics Remote Code Execution vulnerability affecting Microsoft 365 Apps, Microsoft Office, and Microsoft Office Long Term Servicing Channel. It carries a high CVSS score of 7.8, indicating a significant risk where an attacker could achieve full compromise of confidentiality, integrity, and availability. Exploitation requires user interaction (UI:R) and local access (AV:L), but with low attack complexity (AC:L). While not currently listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered some community and media attention, including a mention in a BleepingComputer article regarding Microsoft's February 2022 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:x64:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:x86:* | ||
2013_rtCPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013_rt:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.