cbcvebase.
CVE-2022-21894
published 2022-01-11

CVE-2022-21894: Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability

medium4.4CVSS 3.1
AVLACLPRHUINSUCNIHAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
5.98%
92.5th percentile
Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.1917710.0.10240.19177
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.488610.0.14393.4886
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.245210.0.17763.2452
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.245210.0.17763.2452
microsoftwindows_10_version_1909>= 10.0.0 < 10.0.18363.203710.0.18363.2037
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.146610.0.19042.1466
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.146610.0.19043.1466
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.146610.0.19044.1466
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.43410.0.22000.434
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.202466.3.9600.20246
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.235846.2.9200.23584
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.202466.3.9600.20246
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.488610.0.14393.4886
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.245210.0.17763.2452
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.46910.0.20348.469
microsoftwindows_server_version_20h2>= 10.0.0 < 10.0.19042.146610.0.19042.1466
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1809
msrcwindows_10_version_1909
msrcwindows_10_version_20h2
msrcwindows_10_version_21h1
msrcwindows_10_version_21h2
msrcwindows_11_version_21h2
msrcwindows_8.1

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2022-21894 is a Windows Secure Boot Security Feature Bypass vulnerability; monitor for unauthorized or unexpected modifications to Secure Boot configuration or UEFI variables that could indicate exploitation.
  • The vulnerability affects Windows Secure Boot; patch remediation references KB5009557, KB5009545, KB5009543, KB5009555, KB5009566, KB5009585, KB5009546, KB5009624, KB5009595, KB5009586, KB5009619 — absence of these KBs on monitored hosts indicates unpatched/potentially exploitable systems.
  • Exploitation status is publicly disclosed but not yet observed in the wild at time of advisory; treat any Secure Boot bypass activity on Windows systems as high-priority for investigation.
  • ·Customer action is required to remediate this vulnerability; passive patching or automatic update alone may not be sufficient without administrator intervention.
  • ·The vulnerability is scoped to Windows Secure Boot specifically, not all UEFI implementations; detection efforts should be focused on Windows boot chain components.

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:C/A:N
cvelistv54.4MEDIUM
vulncheck4.4MEDIUM
vendor_msrc4.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.