HIGH
CVE-2022-21882
CVSS
7.8
KEV
Description
Win32k Elevation of Privilege Vulnerability
Summary dbcve.org
Win32k.sys Elevation of Privilege vulnerability allowing a local attacker to gain elevated system privileges via the Windows kernel-mode driver.
Mitigation
Apply Microsoft security updates for CVE-2022-21882; prioritize patching given the high CVSS score and local privilege escalation nature.
Weakness (CWE)
CWE-787
Out-of-bounds Write
EPSS Score
59.21%
Probability of exploitation in next 30 days
99.1th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21882
Patch, Vendor Advisory
http://packetstormsecurity.com/files/166169/Win32k-ConsoleControl-Offset-Confusion-Privilege-Escalation.html
Third Party Advisory, VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-21882
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-21882
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.