Junglewise Threat Intelligence

CVE-2022-21971: Microsoft Windows Runtime Remote Code Execution Vulnerability

CVE-2022-21971 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-08-18

Technologies: Microsoft Windows 10, Microsoft Windows, Microsoft Windows 11, Microsoft Windows Server 2022, Microsoft Windows Server, Microsoft Windows Server 2019. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in Microsoft Windows Runtime due to the access of an uninitialized pointer. The vulnerability requires user interaction and has been observed being exploited in the wild.

Affected products

  • Microsoft Windows 10 1809, 1909, 20H2, 21H1, 21H2
  • Microsoft Windows 11 21H2
  • Microsoft Windows Server 2019 -
  • Microsoft Windows Server 2022 -
  • Microsoft Windows Server 20H2

Timeline

  • 2022-02-14: disclosed: Initial analysis by NIST
  • 2022-08-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-08-18: exploited: Reported as exploited in the wild

Related threats