CVE detail
CVE-2022-21882
Win32k Elevation of Privilege Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
13 source links · newest first
- In 2022, more than 40% of zero-day exploits used in the wild were variations of previous issuesSecurity Affairs
Google’s Threat Analysis Group Google states that more than 40% of zero-day flaws discovered in 2022 were variants of previous issues. The popular Threat Analysis Group (TAG) Maddie Stone wrote Google’s fourth annual year-in-review of zero-day flaws exploited in-the-wild [2021, 2020, 2019], it is built off of the mid-year 2022 review. In 2022, the researchers […]
newssecurityaffairs.comJul 30, 2023, 4:38 PM We analyze two Win32k proof-of-concept exploits, CVE-2021-1732 and CVE-2022-21882. These data-only attacks target the Win32k kernel.
vendorunit42.paloaltonetworks.comJun 20, 2023, 1:00 PM- Inside Win32k Exploitation: Background on Implementations of Win32k and Exploitation MethodologiesUnit42
We analyze Microsoft Windows' GUI, how it functions and some of the history of research into its exploitation.
vendorunit42.paloaltonetworks.comJun 13, 2023, 1:00 PM - Microsoft fixes two actively exploited bugs, one used by BlackLotus bootkit (CVE-2023-29336, CVE-2023-24932)Help Net Security
For May 2023 Patch Tuesday, Microsoft has delivered fixes for 38 CVE-numbered vulnerabilities, including a patch for a Windows bug (CVE-2023-29336) and a Secure Boot bypass flaw (CVE-2023-24932) exploited by attackers in the wild. The two exploited bugs (CVE-2023-29336, CVE-2023-24932) CVE-2023-29336 is a vulnerability that allows attackers to gain SYSTEM privileges. Flagged by researchers with AV maker Avast, it seems probable that it’s being exploited to deliver malware. Microsoft has offered no details about the … More →
newswww.helpnetsecurity.comMay 9, 2023, 6:58 PM - Half of actively exploited zero-day issues in H1 2022 are variants of previous flawsSecurity Affairs
Google Project Zero states that in H1 2022 at least half of zero-day issues exploited in attacks were related to not properly fixed old flaws. Google Project Zero researcher Maddie Stone published a blog post that resumes her speech at the FIRST conference in June 2022, the presentation is titled “0-day In-the-Wild Exploitation in 2022…so […]
newssecurityaffairs.comJul 3, 2022, 1:31 PM Google Project Zero has observed a total of 18 exploited zero-day vulnerabilities in the first half of 2022, at least half of which exist because previous bugs were not properly addressed.
newswww.securityweek.comJul 1, 2022, 11:12 AM- A “light” February 2022 Patch Tuesday that should not be ignoredHelp Net Security
February 2022 Patch Tuesday is here and it’s all-around “light” – light in fixed CVE-numbered vulnerabilities (51), extremely light in critical fixes (50 are “important” and one is “moderate”), and light in exploited vulnerabilities (none of the vulnerabilities are listed as under active attack). Only one is listed as publicly known – CVE-2022-21989, a Windows Kernel EOP flaw – but while there’s apparently a PoC exploit out there (not necessarily public), “Successful exploitation of this … More →
newswww.helpnetsecurity.comFeb 8, 2022, 7:42 PM The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its list of vulnerabilities known to be exploited in malicious attacks with a recently addressed Windows zero-day flaw.
newswww.securityweek.comFeb 7, 2022, 11:06 AM- Security Affairs newsletter Round 352Security Affairs
A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. LockBit ransomware gang claims to have stolen data from PayBito crypto exchange FBI issued […]
newssecurityaffairs.comFeb 6, 2022, 10:07 AM US CISA ordered federal agencies to patch their systems against actively exploited CVE-2022-21882 Windows flaw. The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to address their systems against an actively exploited Windows vulnerability tracked as CVE-2022-21882. “CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence that threat […]
newssecurityaffairs.comFeb 5, 2022, 9:34 AMIf you’re running Windows 10, it’s time to stop delaying those patches and bring your systems up to date as soon…
newswww.malwarebytes.comJan 31, 2022, 5:00 PM- 31st January– Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 31st January, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Hacktivist group from Belarus called “Belarusian Cyber Partisans” has breached the computers systems of Belarusian Railways. Threat actors claim to have encrypted the network and are extorting the Belarusian government, asking for […]
vendorresearch.checkpoint.comJan 31, 2022, 2:37 PM A researcher disclosed an exploit for a Windows local privilege elevation issue (CVE-2022-21882) that allows anyone to gain admin privileges in Windows 10. The security researchers RyeLv has publicly released an exploit for a Windows local privilege elevation flaw (CVE-2022-21882) that allows anyone to gain admin privileges in Windows 10. The Win32k elevation of privilege […]
newssecurityaffairs.comJan 30, 2022, 6:27 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-24521CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-26925CVSS 8.1 · High
Windows LSA Spoofing Vulnerability
- CVE-2022-26904CVSS 7.0 · High
Windows User Profile Service Elevation of Privilege Vulnerability
- CVE-2022-22718CVSS 7.8 · High
Windows Print Spooler Elevation of Privilege Vulnerability
KEV listed4 mentions - CVE-2022-21999CVSS 7.8 · High
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-21971CVSS 7.8 · High
Windows Runtime Remote Code Execution Vulnerability