CVE detail
CVE-2022-41125
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 19.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
No excerpt available.
Mitigationwww.cisa.govNov 9, 2022, 10:15 PM- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41125msrc.microsoft.com
No excerpt available.
Vendor Advisorymsrc.microsoft.comNov 9, 2022, 10:15 PM Microsoft Patch Tuesday updates for November 2022 addressed 64 vulnerabilities, including six actively exploited zero-days. Microsoft Patch Tuesday updates for November 2022 addressed 64 new vulnerabilities in Microsoft Windows and Windows Components; Azure and Azure Real Time Operating System; Microsoft Dynamics; Exchange Server; Office and Office Components; SysInternals; Visual Studio; SharePoint Server; Network Policy Server […]
newssecurityaffairs.comNov 9, 2022, 11:54 AMSoftware security platform Rezilion has expanded its Dynamic Software Bill of Materials (SBOM) capability to support Windows environments. The firm said the move will provide organizations with the tools to efficiently manage software vulnerabilities and meet new regulatory standards, addressing functionality gaps of traditional vulnerability management tools primarily designed for use with Linux OS. Features […]
newswww.csoonline.comNov 9, 2022, 11:00 AM- Microsoft fixes many zero-days under attackHelp Net Security
November 2022 Patch Tuesday is here, with fixes for many vulnerabilities actively exploited in the wild, including CVE-2022-41091, a Windows Mark of the Web bypass flaw, and the ProxyNotShell MS Exchange vulnerabilities. Fixes to prioritize CVE-2022-41091 is a Windows zero-day vulnerability that allows attackers to bypass the Mark of the Web (MOTW) security feature. They can craft a malicious file triggering the flaw and deliver it either via a malicious or compromised website or via … More →
newswww.helpnetsecurity.comNov 8, 2022, 7:53 PM The zero-day attacks against Microsoft’s software products are showing no signs of slowing down.
newswww.securityweek.comNov 8, 2022, 6:40 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-41128CVSS 8.8 · High
Windows Scripting Languages Remote Code Execution Vulnerability
- CVE-2022-41073CVSS 7.8 · High
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2013-3900CVSS 5.5 · Medium
Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the…
- CVE-2023-28252CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2023-23376CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-37969CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability