CVE-2022-21882
KEV ransomwaremassOut-of-Bounds Write LPE in Microsoft Win32k on Windows 10/11 and Windows Server
CISA: Microsoft Win32k Privilege Escalation Vulnerability
CVE-2022-21882 is a Win32k elevation-of-privilege vulnerability caused by an out-of-bounds write (CWE-787) in the Windows kernel's Win32k component, affecting Windows 10 versions 1809 through 21H2, Windows 11 21H2, and Windows Server 2019, 2022, and version 20H2. A local attacker who can already execute code with a low-privileged account can trigger the flaw via Win32k system calls with no user interaction, corrupting kernel memory and escalating to SYSTEM-level privileges. Successful exploitation gives the attacker full control of the compromised host (high confidentiality, integrity, and availability impact), and it is commonly chained after an initial foothold to deploy ransomware or other payloads. Anyone running the affected Windows 10, Windows 11, or Windows Server builds is exposed, because the vulnerable Win32k code ships by default with those operating systems. The flaw is actively exploited in the wild: it is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-04) with known ransomware use, and public proof-of-concept code was released by researchers after disclosure.
What to do: Apply Microsoft's cumulative security updates for Windows 10 (1809–21H2), Windows 11 21H2, and Windows Server 2019/2022/20H2 immediately — the fix shipped in Microsoft's January 2022 Patch Tuesday and is included in all later cumulative updates; per CISA's required action, apply updates per vendor instructions. Prioritize multi-user hosts (RDS/VDI, terminal and jump servers) where local privilege escalation is most damaging, and hunt for post-compromise indicators such as unexpected SYSTEM-level processes, since ransomware operators are known to use this bug after gaining an initial foothold. If patching is delayed, limit local code execution on affected systems and watch EDR telemetry for kernel-level privilege-escalation behavior.
| Microsoft Windows 10 | 1809 |
| Microsoft Windows 10 | 1909 |
| Microsoft Windows 10 | 20H2 |
| Microsoft Windows 10 | 21H1 |
| Microsoft Windows 10 | 21H2 |
| Microsoft Windows 11 | 21H2 |
| Microsoft Windows Server 2019 | all supported builds (as listed by CISA) |
| Microsoft Windows Server 2022 | all supported builds (as listed by CISA) |
| Microsoft Windows Server, version 20H2 | all supported builds (as listed by CISA) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Win32k Elevation of Privilege Vulnerability
- Affected
- Microsoft Win32k
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1809, windows 10 1909, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows server 2019, windows server 2022, windows server 20h2
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H