Executive brief
A type confusion vulnerability (CWE-843) in the Microsoft Windows COM+ Event System Service allows a local attacker to escalate privileges. The vulnerability has been observed being exploited in the wild.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.10240.19507
- Microsoft Windows 11 up to (excluding) 10.0.22621.674
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.1129
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows Server 2008
- Microsoft Windows Server 2012
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
Timeline
- 2022-10-11: disclosed
- 2022-10-11: patched
- 2022-10-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-10-11: exploited: Reported as exploited in the wild at time of publication.