CVE-2022-21882High· 7.0▾ Abyssal⚠ Exploited in the wild0dayPoC availableWin32k Elevation of Privilege Vulnerability
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 38.5 · likelihood 11.8 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Feb 18, 2022
Last analysed / modified upstream
55%
55% → 59%
5 GitHub repos · Metasploit ×1
Added to the CISA catalog on Feb 4, 2022. Federal remediation due Feb 18, 2022. View catalog ↗
Win32k Elevation of Privilege Vulnerability
windows_10_1809 < 10.0.17763.2452windows_10_1909 < 10.0.18363.2037windows_10_20h2 < 10.0.19042.1466windows_10_21h1 < 10.0.19043.1466windows_10_21h2 < 10.0.19044.1466windows_11_21h2 < 10.0.22000.434windows_server_2019 < 10.0.17763.2452windows_server_2022 < 10.0.20348.469windows_server_20h2 < 10.0.19042.1466Upgrade past the affected range:
windows_10_1809 10.0.17763.2452windows_10_1909 10.0.18363.2037windows_10_20h2 10.0.19042.1466windows_10_21h1 10.0.19043.1466windows_10_21h2 10.0.19044.1466windows_11_21h2 10.0.22000.434windows_server_2019 10.0.17763.2452windows_server_2022 10.0.20348.469windows_server_20h2 10.0.19042.1466Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-1054High· 7.0An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory
CVE-2018-8174High· 7.5A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1…
CVE-2021-34486High· 7.8Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-36934High· 7.8An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database
CVE-2024-21338High· 7.8Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-36948High· 7.8Windows Update Medic Service Elevation of Privilege Vulnerability