CVE-2022-21882

HIGH KEV

Win32k ConsoleControl Offset Confusion

Title source: metasploit

Description

Win32k Elevation of Privilege Vulnerability

Exploits (7)

nomisec WORKING POC 465 stars
by KaLendsi · local
https://github.com/KaLendsi/CVE-2022-21882
nomisec WORKING POC 200 stars
by L4ys · local
https://github.com/L4ys/CVE-2022-21882
nomisec WORKING POC 49 stars
by sailay1996 · local
https://github.com/sailay1996/cve-2022-21882-poc
nomisec WORKING POC 8 stars
by David-Honisch · local
https://github.com/David-Honisch/CVE-2022-21882
nomisec WORKING POC 6 stars
by r1l4-i3pur1l4 · local
https://github.com/r1l4-i3pur1l4/CVE-2022-21882
metasploit WORKING POC NORMAL
by BITTER APT, JinQuan, MaDongZe, TuXiaoYi, LiHao, L4ys, KaLendsi, Spencer McIntyre · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/cve_2022_21882_win32k.rb
patchapalooza WORKING POC
by gdabah · local
https://github.com/gdabah/win32k-bugs

Scores

CVSS v3 7.0
EPSS 0.8851
EPSS Percentile 99.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-02-04
VulnCheck KEV 2022-01-11
InTheWild.io 2022-01-11
ENISA EUVD EUVD-2022-27038
CWE
CWE-787
Status published
Products (9)
microsoft/windows_10_1809 < 10.0.17763.2452 (2 CPE variants)
microsoft/windows_10_1909 < 10.0.18363.2037
microsoft/windows_10_20h2 < 10.0.19042.1466
microsoft/windows_10_21h1 < 10.0.19043.1466
microsoft/windows_10_21h2 < 10.0.19044.1466
microsoft/windows_11_21h2 < 10.0.22000.434
microsoft/windows_server_2019 < 10.0.17763.2452
microsoft/windows_server_2022 < 10.0.20348.469
microsoft/windows_server_20h2 < 10.0.19042.1466
Published Jan 11, 2022
KEV Added Feb 04, 2022
Tracked Since Feb 18, 2026