Skip to content
COOEY

EXPOSURES › CVE-2022-22047

CVE-2022-22047

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-07-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-22047 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedprivilege-escalation

A Microsoft Windows vulnerability allowed attackers to escalate privileges to SYSTEM, actively exploited in the wild and impacting DIB organizations using Windows systems.

CVE-2022-22047 is a CSRSS privilege escalation vulnerability allowing SYSTEM-level access. DIB organizations relying on Windows must promptly patch to prevent unauthorized access and potential data compromise, directly impacting NIST 800-171 compliance. Verify patching status and consider compensating controls until remediation.

Shame score — The vulnerability's active exploitation and potential for SYSTEM-level access demonstrates a significant security oversight by Microsoft, requiring immediate attention from DIB organizations.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized