PT-2021-6023 · Microsoft · Windows 11+4

Ryelv

·

Published

2021-04-23

·

Updated

2026-06-13

·

CVE-2022-21882

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows 10 (affected versions not specified) Windows 11 (affected versions not specified) Windows Server 2019 (affected versions not specified) Windows Server 2022 (affected versions not specified)
Description An elevation of privilege issue exists in the Win32k component (win32k.sys) of the Windows NT kernel due to improper access control and a use-after-free flaw. A use-after-free occurs when a program continues to use a pointer after it has been freed, which can lead to memory corruption. By manipulating window objects and their lifetime, an attacker can force the kernel to operate on a freed object under their control, enabling arbitrary kernel read/write capabilities to swap the current process token with the SYSTEM token. This issue has been actively exploited in real-world incidents, including use by ransomware for network propagation.
Recommendations Apply the updates provided by Microsoft in the January Tuesday updates for Windows 10, Windows 11, Windows Server 2019, and Windows Server 2022.

Exploit

Fix

DoS

LPE

Improper Privilege Management

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00596
CVE-2022-21882

Affected Products

Windows
Windows 10
Windows 11
Windows Server 2019
Windows Server 2022