Proof-of-Concept Code Now Available for an Exploited Windows Local Privilege Escalation Vulnerability
ID: eef1767e-bc7f-5a80-944e-54aa90c3ba00
STIX ID: report--eef1767e-bc7f-5a80-944e-54aa90c3ba00
Feed Name: FortiGuard Threat Signals
FortiGuard Labs reports that CVE-2022-21882, a Win32k.sys local privilege escalation vulnerability (CVSS 7.0), is being exploited in the wild and that a publicly available proof-of-concept has been released; Microsoft issued a patch on January 11, 2022. The advisory notes increased attack risk due to the PoC, confirms FortiGuard IPS and AV signatures covering the issue, and advises that the flaw is typically used by attackers who already have local/authenticated access or as part of chained exploits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
