ZeroHour

CVE-2022-41033

KEVmass1

Local Privilege Escalation in Microsoft Windows COM+ Event System Service

CISA: Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
2%p75
Published
()
KEV added
AI analysis

CVE-2022-41033 is an elevation-of-privilege flaw in the Microsoft Windows COM+ Event System Service, classified under CWE-843 (access of a resource using an incompatible type). It is triggered locally: an attacker who can already execute code on a machine with limited (low-privilege) rights can exploit the vulnerable service with no user interaction, per the CVSS vector (AV:L/AC:L/PR:L/UI:N). Successful exploitation elevates the attacker to the highest local privilege level, with high impact on the confidentiality, integrity, and availability of the system — a typical post-compromise privilege-escalation step for an attacker who already has a foothold. The flaw affects the Windows releases in the CISA CPE data — Windows 7, 8.1, RT 8.1, Windows 10 (1507, 1607, 1809, 20H2, 21H1, 21H2), Windows 11 (21H2, 22H2), and Windows Server 2008 — meaning effectively the broad Windows installed base. Microsoft patched it in the October 2022 Patch Tuesday release and it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-11 as exploited in the wild; no public PoC is known, ransomware use is unknown, and EPSS currently estimates a 1.7% probability of exploitation in the next 30 days (75th percentile).

What to do: Apply the October 2022 Windows security updates (or any later cumulative update) on all affected Windows clients and servers, prioritizing hosts where low-privileged users can run code, such as workstations, terminal/RDS servers, and VDI images — this also satisfies the CISA KEV required action. Until patched, treat any unprivileged compromise of a Windows host as potentially escalated to full local privilege, and restrict untrusted local code execution where possible. Verify remediation by confirming the October 2022 (or newer) cumulative update level on each host rather than relying on OS version alone.

Affected
microsoft Windows 101507, 1607, 1809, 20H2, 21H1, 21H2 (CPE-listed releases)
microsoft Windows 1121H2, 22H2 (CPE-listed releases)
microsoft Windows 7
microsoft Windows 8.1
microsoft Windows RT 8.1
microsoft Windows Server 2008
Estimated exposure
masson the order of 1 billion Windows devices (essentially the entire supported Windows client and server installed base) — The affected versions span essentially the whole supported Windows client and server line, and Windows runs on roughly 1.4 billion active devices worldwide, so the plausibly affected installed base is on the order of a billion systems…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows COM+ Event System Service Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows COM+ Event System Service
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows 11 22h2, windows 7, windows 8.1, windows rt 8.1, windows server 2008
Weakness
CWE-843
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news