CVE-2022-35841 is a high-severity Remote Code Execution vulnerability in the Windows Enterprise App Management Service, affecting Windows 10, 11, and various Windows Server versions. With a CVSS score of 8.8, it allows an authenticated attacker to execute arbitrary code remotely with high impact on confidentiality, integrity, and availability, requiring low privileges and no user interaction. While not currently listed in CISA's KEV catalog, it has a high EPSS score and FAUCET Risk Score, indicating a significant likelihood of exploitation. Although no public exploit code is available via Metasploit, Nuclei, or ExploitDB, it has garnered community discussion and media coverage, including a mention in Microsoft's September 2022 Patch Tuesday, suggesting awareness among threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x86:* | ||
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:arm64:* | ||
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:x64:* | ||
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:x86:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.