EXPOSURES › CVE-2022-41125
CVE-2022-41125
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
exploited-in-wildunpatched
CVE-2022-41125: Unpatched Windows CNG Key Isolation Service Privilege Escalation exploit active in wild
An unpatched vulnerability in Microsoft's Windows CNG Key Isolation Service allows attackers to gain SYSTEM-level privileges, posing a high risk to DIB systems.
Shame score — Active exploitation of a critical Windows vulnerability by an unknown attacker in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
AFFECTED FEDRAMP PRODUCTS · 4
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |