PT-2022-1714 · Microsoft · Windows Kernel+1

Published

2022-02-08

·

Updated

2023-08-08

·

CVE-2022-21989

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Kernel (affected versions not specified)
Description The issue is related to insufficient access control in the Windows Kernel, allowing an attacker to elevate their privileges. This vulnerability can be exploited to gain access to resources at a higher integrity level than the AppContainer environment. It is reported that a successful attack can be executed from an AppContainer with low privileges, enabling the attacker to execute code or access resources at a higher level of integrity. The vulnerability affects a wide range of Windows products and components.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00965
CVE-2022-21989

Affected Products

Windows
Windows Kernel