CVE-2022-21971
KEVmassUninitialized Pointer RCE in Windows Runtime on Windows 10/11 and Windows Server
CISA: Microsoft Windows Runtime Remote Code Execution Vulnerability
CVE-2022-21971 is a remote code execution flaw in the Microsoft Windows Runtime caused by access to an uninitialized pointer (CWE-824). It is triggered locally: an attacker must convince a user (no privileges required) to open or run a specially crafted application or file, which then corrupts memory through the Windows Runtime component. Successful exploitation lets the attacker execute arbitrary code in the context of the affected user, with impacts to confidentiality, integrity, and availability at that user's privilege level, so any user of an affected Windows release is a potential target. Affected products include Windows 10 versions 1809 through 21H2, Windows 11 21H2, and Windows Server 2019, 2022, and 20H2. The flaw is confirmed as exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-18 — and EPSS assigns it a 53.9% probability of exploitation within 30 days (99th percentile), though no public PoC or specific ransomware use is documented.
What to do: Apply Microsoft's security updates addressing CVE-2022-21971 (fixed in the January 2022 Patch Tuesday cumulative updates) to all Windows 10 1809–21H2, Windows 11 21H2, and Windows Server 2019/2022/20H2 systems, prioritizing endpoints used to open untrusted files and any servers on aged builds. Confirm remediation by checking that the relevant cumulative update is installed on each host. Until patched, warn users against opening files or apps from untrusted sources and watch for suspicious child-process activity tied to user-initiated file opens, since exploitation requires user interaction.
| microsoft Windows 10 | 1809, 1909, 20H2, 21H1, 21H2 |
| microsoft Windows 11 | 21H2 |
| microsoft Windows Server 2019 | all editions covered by the CISA/CPE listing |
| microsoft Windows Server 2022 | all editions covered by the CISA/CPE listing |
| microsoft Windows Server 20H2 | 20H2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Runtime Remote Code Execution Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1809, windows 10 1909, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows server 2019, windows server 2022, windows server 20h2
- Weakness
- CWE-824
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H