HIGH

CVE-2022-21882

Microsoft Windows 10 1809 2022-01-11 CVSS v3.1
CVSS
7.8
KEV

Description

Win32k Elevation of Privilege Vulnerability

Summary dbcve.org

Win32k.sys Elevation of Privilege vulnerability allowing a local attacker to gain elevated system privileges via the Windows kernel-mode driver.

Mitigation

Apply Microsoft security updates for CVE-2022-21882; prioritize patching given the high CVSS score and local privilege escalation nature.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

59.21%
Probability of exploitation in next 30 days
99.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE