ZeroHour

CVE-2022-41125

KEVmass1

Local Privilege Escalation in Microsoft Windows CNG Key Isolation Service

CISA: Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
3%p87
Published
()
KEV added
AI analysis

CVE-2022-41125 is an elevation of privilege vulnerability (an out-of-bounds write, CWE-787) in the Windows CNG Key Isolation Service. A local attacker who already has the ability to execute low-privileged code on a vulnerable Windows system can trigger the flaw without user interaction. Successful exploitation grants the attacker elevated (SYSTEM-level) privileges, giving high confidentiality, integrity and availability impact on the host. The flaw affects a broad range of Windows 10, Windows 11, Windows 8.1 and Windows Server versions, meaning nearly the entire mainstream Windows installed base is in scope. It is being actively exploited in the wild: it was added to the CISA Known Exploited Vulnerabilities catalog on 2022-11-08 and was one of six actively exploited zero-days fixed in Microsoft's November 2022 Patch Tuesday release.

What to do: Apply the November 2022 Windows security updates (or any later cumulative update) from Microsoft per the vendor's instructions, and prioritize this patch since the flaw is confirmed actively exploited. Inventory endpoints and servers running the affected Windows 10, 11, 8.1 and Server 2012/2016 versions and verify each has received the November 2022 or newer cumulative update. No public exploit details or mitigations are published, so patching is the primary remediation; treat any unpatched host as at elevated risk.

Affected
microsoft Windows 101507, 1607, 1809, 20H2, 21H1, 21H2, 22H2
microsoft Windows 1121H2, 22H2
microsoft Windows 8.1all supported editions per vendor advisory
microsoft Windows Server 2012all supported editions per vendor advisory
microsoft Windows Server 2016all supported editions per vendor advisory
Estimated exposure
mass≈1 billion+ Windows installations (affected versions span the mainstream Windows 10/11 desktop and Windows Server installed base) — The affected product list covers nearly all supported Windows 10/11 client builds — an installed base of well over a billion devices based on public desktop market-share figures — plus Windows 8.1 and Windows Server 2012/2016 deployments,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 8.1, windows server 2012, windows server 2016
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news