CVE-2022-21967
published 2022-03-09CVE-2022-21967: Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability
PriorityP432high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.66%
47.4th percentile
Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19235 | 10.0.10240.19235 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5006 | 10.0.14393.5006 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2686 | 10.0.17763.2686 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2686 | 10.0.17763.2686 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2158 | 10.0.18363.2158 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1586 | 10.0.19042.1586 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1586 | 10.0.19043.1586 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1586 | 10.0.19044.1586 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.556 | 10.0.22000.556 |
| msrc | windows_10_for_32-bit_systems | — | — |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_10_version_1909_for_32-bit_systems | — | — |
| msrc | windows_10_version_1909_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1909_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h3hh-m6r7-4q65: Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-03-10
CVE-2022-21967 [HIGH] CWE-269 GHSA-h3hh-m6r7-4q65: Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability
Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability.
Microsoft
Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability
vendor_msrc·2022-03-08·CVSS 7.0
CVE-2022-21967 [HIGH] Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability
Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
FAQ: The security updates for this vulnerability are all Windows operating systems. Are the other Windows devices in my network vulnerable?
No, this vulnerability only manifests in the Windows OS running in an Xbox environment. Non-Xbox environments cannot be exploited by this vulnerability.
XBox: XBox
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software
No detection rules found.
No public exploits indexed.
Krebs
Microsoft Patch Tuesday, March 2022 Edition
blogs_krebs·2022-03-09·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, March 2022 Edition
Microsoft on Tuesday released software updates to plug at least 70 security holes in its Windows operating systems and related software. For the second month running, there are no scary zero-day threats looming for Windows users, and relatively few “critical” fixes. And yet we know from experience that attackers are already trying to work out how to turn these patches into a roadmap for exploiting the flaws they fix. Here’s a look at the security weaknesses Microsoft says are most likely to be targeted first.
Greg Wiseman , product manager at Rapid7 , notes that three vulnerabilities fixed this month have been previously disclosed, potentially giving attackers a head start in working out how to exploit them. Those include remote code execution bugs CVE-2022-24512 , affecting .NET and Visu
Krebs
Microsoft Patch Tuesday, March 2022 Edition
blogs_krebs·2022-03-09·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, March 2022 Edition
Microsoft on Tuesday released software updates to plug at least 70 security holes in its Windows operating systems and related software. For the second month running, there are no scary zero-day threats looming for Windows users, and relatively few “critical” fixes. And yet we know from experience that attackers are already trying to work out how to turn these patches into a roadmap for exploiting the flaws they fix. Here’s a look at the security weaknesses Microsoft says are most likely to be targeted first.
Greg Wiseman, product manager at Rapid7, notes that three vulnerabilities fixed this month have been previously disclosed, potentially giving attackers a head start in working out how to exploit them. Those include remote code execution bugs CVE-2022-24512, affecting .NET and Visual
2022-03-09
Published