Umbra Wiki cve cve/CVE-2022-41125
Back to wiki

CVE-2022-41125 — Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

provenance: imported · CVE: CVE-2022-41125

CVE-2022-41125: Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Microsoft
Product Windows
Date added 2022-11-08
Due date 2022-12-09
Ransomware campaign use Unknown

Description

Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41125; https://nvd.nist.gov/vuln/detail/CVE-2022-41125

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-41125
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog