HIGH

CVE-2022-41033

Microsoft Windows 10 1507 2022-10-11 CVSS v3.1
CVSS
7.8
KEV

Description

Windows COM+ Event System Service Elevation of Privilege Vulnerability

Summary dbcve.org

This is a local elevation of privilege vulnerability in the Windows COM+ Event System Service. The vulnerability allows a local authenticated attacker to execute code with elevated SYSTEM privileges, potentially taking full control of the affected system.

Mitigation

Apply the Microsoft security update for CVE-2022-41033 to all affected Windows systems. Prioritize domain controllers and systems with high privilege access given the SYSTEM-level impact.

Patch Commit

Weakness (CWE)

CWE-843 Type Confusion

EPSS Score

1.7%
Probability of exploitation in next 30 days
76.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE