HIGH
CVE-2022-41033
CVSS
7.8
KEV
Description
Windows COM+ Event System Service Elevation of Privilege Vulnerability
Summary dbcve.org
This is a local elevation of privilege vulnerability in the Windows COM+ Event System Service. The vulnerability allows a local authenticated attacker to execute code with elevated SYSTEM privileges, potentially taking full control of the affected system.
Mitigation
Apply the Microsoft security update for CVE-2022-41033 to all affected Windows systems. Prioritize domain controllers and systems with high privilege access given the SYSTEM-level impact.
Weakness (CWE)
CWE-843
Type Confusion
EPSS Score
1.7%
Probability of exploitation in next 30 days
76.2th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41033
Patch, Vendor Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41033
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-41033
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.