CVE-2022-21899
published 2022-01-11CVE-2022-21899: Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
1.43%
70.0th percentile
Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19177 | 10.0.10240.19177 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25829 | 6.1.7601.25829 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25829 | 6.1.7601.25829 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20246 | 6.3.9600.20246 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.25829 | 6.1.7601.25829 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23584 | 6.2.9200.23584 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20246 | 6.3.9600.20246 |
| msrc | windows_10_for_32-bit_systems | — | — |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_7_for_32-bit_systems_service_pack_1 | — | — |
| msrc | windows_7_for_x64-based_systems_service_pack_1 | — | — |
| msrc | windows_8.1_for_32-bit_systems | — | — |
| msrc | windows_8.1_for_x64-based_systems | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008_r2_for_x64-based_systems_service_pack_1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-67j8-976x-9cmm: Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
ghsa_unreviewed·2022-01-12
CVE-2022-21899 [MEDIUM] CWE-863 GHSA-67j8-976x-9cmm: Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
Windows Extensible Firmware Interface Security Feature Bypass Vulnerability.
Microsoft
Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
vendor_msrc·2022-01-11·CVSS 5.5
CVE-2022-21899 [MEDIUM] Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
Windows UEFI: Windows UEFI
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009585
Reference: https://support.microsoft.com/help/5009585
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009610
Reference: https://support.microsoft.com/help/5009610
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009621
Reference: https://support.microsoft.com/help/5009621
Reference: https://catalog.update.microsoft.com/v7/s
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-01-11
Published