ZeroHour

CVE-2022-21882

KEV ransomwaremass

Out-of-Bounds Write LPE in Microsoft Win32k on Windows 10/11 and Windows Server

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
59%p99
Published
()
KEV added
AI analysis

CVE-2022-21882 is a Win32k elevation-of-privilege vulnerability caused by an out-of-bounds write (CWE-787) in the Windows kernel's Win32k component, affecting Windows 10 versions 1809 through 21H2, Windows 11 21H2, and Windows Server 2019, 2022, and version 20H2. A local attacker who can already execute code with a low-privileged account can trigger the flaw via Win32k system calls with no user interaction, corrupting kernel memory and escalating to SYSTEM-level privileges. Successful exploitation gives the attacker full control of the compromised host (high confidentiality, integrity, and availability impact), and it is commonly chained after an initial foothold to deploy ransomware or other payloads. Anyone running the affected Windows 10, Windows 11, or Windows Server builds is exposed, because the vulnerable Win32k code ships by default with those operating systems. The flaw is actively exploited in the wild: it is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-04) with known ransomware use, and public proof-of-concept code was released by researchers after disclosure.

What to do: Apply Microsoft's cumulative security updates for Windows 10 (1809–21H2), Windows 11 21H2, and Windows Server 2019/2022/20H2 immediately — the fix shipped in Microsoft's January 2022 Patch Tuesday and is included in all later cumulative updates; per CISA's required action, apply updates per vendor instructions. Prioritize multi-user hosts (RDS/VDI, terminal and jump servers) where local privilege escalation is most damaging, and hunt for post-compromise indicators such as unexpected SYSTEM-level processes, since ransomware operators are known to use this bug after gaining an initial foothold. If patching is delayed, limit local code execution on affected systems and watch EDR telemetry for kernel-level privilege-escalation behavior.

Affected
Microsoft Windows 101809
Microsoft Windows 101909
Microsoft Windows 1020H2
Microsoft Windows 1021H1
Microsoft Windows 1021H2
Microsoft Windows 1121H2
Microsoft Windows Server 2019all supported builds (as listed by CISA)
Microsoft Windows Server 2022all supported builds (as listed by CISA)
Microsoft Windows Server, version 20H2all supported builds (as listed by CISA)
Estimated exposure
mass≈1 billion Windows 10/11 devices plus millions of Windows Server instances (installed-base estimate) — Microsoft has reported over 1.4 billion monthly-active Windows 10/11 devices and Windows Server is ubiquitous in enterprise datacenters, and every listed build ships the vulnerable Win32k code by default; because the flaw is local (AV:L),…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Win32k Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1809, windows 10 1909, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows server 2019, windows server 2022, windows server 20h2
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news