ZeroHour

CVE-2022-21971

KEVmass

Uninitialized Pointer RCE in Windows Runtime on Windows 10/11 and Windows Server

CISA: Microsoft Windows Runtime Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
54%p99
Published
()
KEV added
AI analysis

CVE-2022-21971 is a remote code execution flaw in the Microsoft Windows Runtime caused by access to an uninitialized pointer (CWE-824). It is triggered locally: an attacker must convince a user (no privileges required) to open or run a specially crafted application or file, which then corrupts memory through the Windows Runtime component. Successful exploitation lets the attacker execute arbitrary code in the context of the affected user, with impacts to confidentiality, integrity, and availability at that user's privilege level, so any user of an affected Windows release is a potential target. Affected products include Windows 10 versions 1809 through 21H2, Windows 11 21H2, and Windows Server 2019, 2022, and 20H2. The flaw is confirmed as exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-18 — and EPSS assigns it a 53.9% probability of exploitation within 30 days (99th percentile), though no public PoC or specific ransomware use is documented.

What to do: Apply Microsoft's security updates addressing CVE-2022-21971 (fixed in the January 2022 Patch Tuesday cumulative updates) to all Windows 10 1809–21H2, Windows 11 21H2, and Windows Server 2019/2022/20H2 systems, prioritizing endpoints used to open untrusted files and any servers on aged builds. Confirm remediation by checking that the relevant cumulative update is installed on each host. Until patched, warn users against opening files or apps from untrusted sources and watch for suspicious child-process activity tied to user-initiated file opens, since exploitation requires user interaction.

Affected
microsoft Windows 101809, 1909, 20H2, 21H1, 21H2
microsoft Windows 1121H2
microsoft Windows Server 2019all editions covered by the CISA/CPE listing
microsoft Windows Server 2022all editions covered by the CISA/CPE listing
microsoft Windows Server 20H220H2
Estimated exposure
masshundreds of millions of Windows 10/11 and Windows Server devices worldwide — The affected versions span the mainstream Windows 10/11 desktop and Windows Server install base (Windows 10/11 alone run on over a billion devices), so the plausible pool of unpatched endpoints and servers is in the hundreds of millions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Runtime Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1809, windows 10 1909, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows server 2019, windows server 2022, windows server 20h2
Weakness
CWE-824
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news