CVE-2022-37983 is a Microsoft DWM Core Library Elevation of Privilege vulnerability affecting Windows 10, 11, and Server versions. With a CVSS score of 7.8 (HIGH), it allows a local attacker with low privileges to achieve high impact on confidentiality, integrity, and availability without user interaction. While not currently in CISA's KEV catalog, this vulnerability was reportedly exploited as a zero-day in attacks prior to its October 2022 patch, as highlighted by media coverage. Despite this, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and community discussion remains low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:arm64:* | ||
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:x64:* | ||
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:x86:* | ||
21h1CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:arm64:* | ||
21h1CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.