ZeroHour

CVE-2022-22047

KEVmass

Local Privilege Escalation in Windows CSRSS Affects Nearly All Windows Versions

CISA: Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
19%p97
Published
()
KEV added
AI analysis

CVE-2022-22047 is an elevation-of-privilege vulnerability in the Windows Client Server Run-time Subsystem (CSRSS), a core user-mode process that handles console and system tasks, caused by an untrusted search path (CWE-426). An attacker who already has a low-privileged foothold on a Windows machine can trigger the flaw locally, with no user interaction, to elevate to SYSTEM/administrator-level privileges. Because CSRSS is present on essentially every Windows installation, the affected population spans Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H2), Windows 11 21H2, and Windows Server 2008 and 2012, meaning virtually every Windows desktop, laptop, and server in active use is potentially affected. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on July 12, 2022 with an August 2 patch deadline for federal agencies, and EPSS assigns it an 18.8% probability of exploitation within 30 days (97th percentile).

What to do: Apply Microsoft's July 12, 2022 (Patch Tuesday) security updates immediately across all affected releases, including Windows 7, 8.1, RT 8.1, and Server 2008/2012, where fixes arrive through the same July update servicing; CISA's KEV deadline for federal agencies is August 2, 2022. Treat any host where a local attacker has executed code as potentially compromised to SYSTEM level, and hunt for post-exploitation activity. Keep monitoring vendor guidance, as recent reporting suggests some patched Windows attack surfaces may still be exploitable, so continue applying follow-on Windows updates as they ship.

Affected
microsoft Windows 101507
microsoft Windows 101607
microsoft Windows 101809
microsoft Windows 1020H2
microsoft Windows 1021H1
microsoft Windows 1021H2
microsoft Windows 1121H2
microsoft Windows 7all (per CISA listing)
microsoft Windows 8.1all (per CISA listing)
microsoft Windows RT 8.1all (per CISA listing)
microsoft Windows Server 2008all (per CISA listing)
microsoft Windows Server 2012all (per CISA listing)
Estimated exposure
mass≈1 billion+ Windows devices and servers (the affected list spans Windows 7 through Windows 11 and legacy server releases) — CSRSS ships on every Windows system, and public OS market-share data puts the active Windows installed base at well over a billion desktops plus millions of servers, nearly all of which fall within the listed affected releases.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012
Weakness
CWE-426
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news