EXPOSURES › CVE-2022-22047
CVE-2022-22047
HIGH ⌖ ON CISA KEV · EXPLOITEDA Microsoft Windows vulnerability allowed attackers to escalate privileges to SYSTEM, actively exploited in the wild and impacting DIB organizations using Windows systems.
CVE-2022-22047 is a CSRSS privilege escalation vulnerability allowing SYSTEM-level access. DIB organizations relying on Windows must promptly patch to prevent unauthorized access and potential data compromise, directly impacting NIST 800-171 compliance. Verify patching status and consider compensating controls until remediation.
Shame score — The vulnerability's active exploitation and potential for SYSTEM-level access demonstrates a significant security oversight by Microsoft, requiring immediate attention from DIB organizations.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |