Executive brief
The Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an out-of-bounds write vulnerability (CWE-787). A local attacker can exploit this flaw to escalate privileges to SYSTEM-level.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.10240.19567 (1507), 10.0.14393.5501 (1607), 10.0.17763.3650 (1809), 10.0.19042.2251 (20H2), 10.0.19043.2251 (21H1), 10.0.19044.2251 (21H2), 10.0.19045.2251 (22H2)
- Microsoft Windows 11 up to (excluding) 10.0.22000.1219 (21H2), 10.0.22621.819 (22H2)
- Microsoft Windows Server 2012 R2 and base versions
- Microsoft Windows Server 2016 up to (excluding) 10.0.14393.5501
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.3650
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.1249
- Microsoft Windows 8.1 All versions
- Microsoft Windows 7 SP1
Timeline
- 2022-11-08: disclosed: Vulnerability published by Microsoft
- 2022-11-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-11-08: patched: Microsoft released security updates to address the issue
- 2022-11-08: exploited: Reported as exploited in the wild at time of publication