CVE-2022-21894

MEDIUM EXPLOITED IN THE WILD

Microsoft Windows 10 - Incorrect Authorization

Title source: rule

Description

Secure Boot Security Feature Bypass Vulnerability

Exploits (6)

nomisec WORKING POC 349 stars
by Wack0 · local
https://github.com/Wack0/CVE-2022-21894
nomisec WORKING POC 15 stars
by ASkyeye · local
https://github.com/ASkyeye/CVE-2022-21894-Payload
nomisec WORKING POC 10 stars
by Wack0 · local
https://github.com/Wack0/batondrop_armv7
nomisec WORKING POC 3 stars
by nova-master · local
https://github.com/nova-master/CVE-2022-21894-Payload-New
nomisec WRITEUP
by qjawls2003 · poc
https://github.com/qjawls2003/BlackLotus-Detection
nomisec SCANNER
by bakedmuffinman · poc
https://github.com/bakedmuffinman/BlackLotusDetection

Scores

CVSS v3 4.4
EPSS 0.4093
EPSS Percentile 97.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Details

VulnCheck KEV 2023-03-01
InTheWild.io 2023-03-01
CWE
CWE-863
Status published
Products (15)
microsoft/windows_10 (2 CPE variants)
microsoft/windows_10 20h2 (3 CPE variants)
microsoft/windows_10 21h1 (3 CPE variants)
microsoft/windows_10 21h2 (3 CPE variants)
microsoft/windows_10 1607 (2 CPE variants)
microsoft/windows_10 1809 (3 CPE variants)
microsoft/windows_10 1909 (3 CPE variants)
microsoft/windows_11 (2 CPE variants)
microsoft/windows_8.1 (2 CPE variants)
microsoft/windows_server 20h2
... and 5 more
Published Jan 11, 2022
Tracked Since Feb 18, 2026