CVE-2022-22047
KEVmassLocal Privilege Escalation in Windows CSRSS Affects Nearly All Windows Versions
CISA: Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability
CVE-2022-22047 is an elevation-of-privilege vulnerability in the Windows Client Server Run-time Subsystem (CSRSS), a core user-mode process that handles console and system tasks, caused by an untrusted search path (CWE-426). An attacker who already has a low-privileged foothold on a Windows machine can trigger the flaw locally, with no user interaction, to elevate to SYSTEM/administrator-level privileges. Because CSRSS is present on essentially every Windows installation, the affected population spans Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H2), Windows 11 21H2, and Windows Server 2008 and 2012, meaning virtually every Windows desktop, laptop, and server in active use is potentially affected. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on July 12, 2022 with an August 2 patch deadline for federal agencies, and EPSS assigns it an 18.8% probability of exploitation within 30 days (97th percentile).
What to do: Apply Microsoft's July 12, 2022 (Patch Tuesday) security updates immediately across all affected releases, including Windows 7, 8.1, RT 8.1, and Server 2008/2012, where fixes arrive through the same July update servicing; CISA's KEV deadline for federal agencies is August 2, 2022. Treat any host where a local attacker has executed code as potentially compromised to SYSTEM level, and hunt for post-exploitation activity. Keep monitoring vendor guidance, as recent reporting suggests some patched Windows attack surfaces may still be exploitable, so continue applying follow-on Windows updates as they ship.
| microsoft Windows 10 | 1507 |
| microsoft Windows 10 | 1607 |
| microsoft Windows 10 | 1809 |
| microsoft Windows 10 | 20H2 |
| microsoft Windows 10 | 21H1 |
| microsoft Windows 10 | 21H2 |
| microsoft Windows 11 | 21H2 |
| microsoft Windows 7 | all (per CISA listing) |
| microsoft Windows 8.1 | all (per CISA listing) |
| microsoft Windows RT 8.1 | all (per CISA listing) |
| microsoft Windows Server 2008 | all (per CISA listing) |
| microsoft Windows Server 2012 | all (per CISA listing) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012
- Weakness
- CWE-426
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H