

CVE-2022-21989 - Security Update Guide - Microsoft - Windows Kernel Elevation of...
source link: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-21989
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

-
- Customer Guidance
-
-
Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-21989Released: Feb 8, 2022
Please see Common Vulnerability Scoring System for more information on the definition of these metrics.
Exploitability
Why is Attack Complexity marked as High for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
What is meant by scope change for this particular vulnerability?
In this case, a successful attack could be performed from a low privilege AppContainer. The attacker could elevate their privileges and execute code or access resources at a higher integrity level than that of the AppContainer execution environment.
Acknowledgements
- Anonymous
Security Updates
Disclaimer
Revisions
Information published.
Recommend
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK