HIGH

CVE-2022-41125

Microsoft Windows 10 1507 2022-11-09 CVSS v3.1
CVSS
7.8
KEV

Description

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

Summary dbcve.org

Windows CNG Key Isolation Service Elevation of Privilege vulnerability (CVSS 7.8). This is a local privilege escalation vulnerability in the Windows CNG (Cryptographic Next Generation) Key Isolation service that allows an authenticated low-privileged user to gain elevated (SYSTEM) privileges by exploiting improper access control in the service's key isolation mechanism.

Mitigation

Apply the Microsoft security update for CVE-2022-41125. Verify the patch has been successfully deployed via Windows Update or your organization's patch management system.

Patch Commit

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

3.05%
Probability of exploitation in next 30 days
87th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE