CVE detail
CVE-2022-22047
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
Deploying security patches as quickly as possible remains one of the best ways to prevent most security breaches, as attackers usually rely on exploits for publicly known vulnerabilities that have a patch available — the so-called n-day exploits. But mitigating the risk from vulnerabilities unknown to the affected software developers and don’t have a patch […]
newswww.csoonline.comMar 22, 2023, 7:38 PMWe soon close out the security year of 2022. Only time will tell what 2023 will bring, but for IT and security admins of Microsoft networks, 2022 has been the year of blended attacks, on-premises Exchange Server flaws, and vulnerabilities needing more than patching to mitigate. Here’s a month-by-month look at the past year. January: […]
newswww.csoonline.comDec 8, 2022, 10:00 AM- 1st August – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 1st August, please download our Threat Intelligence Bulletin. Top Attacks and Breaches The LockBit Ransomware gang has claimed the attack on Italy’s tax agency, the Internal Revenue Service. According to LockBit’s message on their dark web site, the group stole 100 GB of sensitive […]
vendorresearch.checkpoint.comAug 1, 2022, 2:44 PM Microsoft linked a private-sector offensive actor (PSOA) to attacks using multiple zero-day exploits for its Subzero malware. The Microsoft Threat Intelligence Center (MSTIC) and the Microsoft Security Response Center (MSRC) researchers linked a threat group known as Knotweed to an Austrian surveillance firm named DSIRF, known for using multiple Windows and Adobe zero-day exploits. The […]
newssecurityaffairs.comJul 28, 2022, 11:04 AMMalware hunters at Microsoft have caught an Austrian hack-for-hire company exploiting zero-day flaws in Windows and Adobe software products in “limited and targeted attacks” against European and Central American computer users.
newswww.securityweek.comJul 27, 2022, 4:17 PM- 18th July – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 18th July, please download our Threat Intelligence Bulletin. Top Attacks and Breaches A callback phishing campaign has been observed targeting corporate networks while impersonating known cybersecurity companies – the emails mention an alleged threat in the target’s network, asking them to call the company […]
vendorresearch.checkpoint.comJul 18, 2022, 2:01 PM - Week in review: Kali Linux gets on Linode, facial recognition defeated, Log4j exploitationHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Dealing with threats and preventing sensitive data loss Recently, Normalyze, a data-first cloud security platform, came out of stealth with $22.2M in Series A funding. This was the perfect time to catch up with co-founder and CEO Amer Deeba. In this interview with Help Net Security, he talks about the path data security as well as visibility challenges. Who are … More →
newswww.helpnetsecurity.comJul 17, 2022, 8:30 AM been released this week, with 84 total vulnerabilities fixed including one actively exploited zero-day. The zero-day ( CVE-2022-22047 ) is a privilege escalation flaw affecting Windows Client/Server Runtime Submission (CSRSS), the exploitation of which could grant attackers system privileges. What's behind the explosion in zero-day exploits? Microsoft
newswww.itpro.comJul 13, 2022, 9:56 AM- Microsoft fixes exploited zero-day in Windows CSRSS (CVE-2022-22047)Help Net Security
The July 2022 Patch Tuesday is upon us and has brought fixes for 84 CVEs in various Microsoft products, including an actively exploited zero-day: CVE-2022-22047, an elevation of privilege bug in Windows’ Client/Server Runtime Subsystem (CSRSS). “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” Microsoft noted, but the attacker must first gain access to the system, usually by exploiting a separate code execution bug. Is it being used in widespread or targeted … More →
newswww.helpnetsecurity.comJul 12, 2022, 7:44 PM Microsoft has issued an urgent Patch Tuesday bulletin to warn of in-the-wild zero-day exploitation of a privilege escalation flaw in the Windows operating system.
newswww.securityweek.comJul 12, 2022, 6:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-35747CVSS 5.9 · Medium
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
1 mention - CVE-2022-35743CVSS 7.8 · High
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
- CVE-2022-34713CVSS 7.8 · High
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
KEV listed10 mentions - CVE-2022-30190CVSS 7.8 · High
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnera…
KEV listed54 mentions - CVE-2022-26925CVSS 8.1 · High
Windows LSA Spoofing Vulnerability
- CVE-2022-26904CVSS 7.0 · High
Windows User Profile Service Elevation of Privilege Vulnerability