CVE-2022-21971
published 2022-02-09CVE-2022-21971: Windows Runtime Remote Code Execution Vulnerability
PriorityP182high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-09-08
Exploited in the wild
EPSS
53.65%
98.9th percentile
Windows Runtime Remote Code Execution Vulnerability
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1809 | < 10.0.17763.2565 | 10.0.17763.2565 |
| microsoft | windows_10_1909 | < 10.0.18363.2094 | 10.0.18363.2094 |
| microsoft | windows_10_20h2 | < 10.0.19042.1526 | 10.0.19042.1526 |
| microsoft | windows_10_21h1 | < 10.0.19043.1526 | 10.0.19043.1526 |
| microsoft | windows_10_21h2 | < 10.0.19044.1526 | 10.0.19044.1526 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2565 | 10.0.17763.2565 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2565 | 10.0.17763.2565 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2094 | 10.0.18363.2094 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1526 | 10.0.19042.1526 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1526 | 10.0.19043.1526 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1526 | 10.0.19044.1526 |
| microsoft | windows_11_21h2 | < 10.0.22000.493 | 10.0.22000.493 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.493 | 10.0.22000.493 |
| microsoft | windows_server_2019 | < 10.0.17763.2565 | 10.0.17763.2565 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.2565 | 10.0.17763.2565 |
| microsoft | windows_server_2022 | < 10.0.20348.524 | 10.0.20348.524 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.524 | 10.0.20348.524 |
| microsoft | windows_server_20h2 | < 10.0.19042.1526 | 10.0.19042.1526 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1526 | 10.0.19042.1526 |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector is local with required user interaction — delivery likely via social engineering where victim downloads and opens a specially crafted file, triggering local code execution via Windows Runtime. ↗
- ·Despite the 'Remote Code Execution' title, the attack vector is local (AV:L) — the word 'Remote' refers to the attacker's location, not network-based exploitation. Detection should focus on local execution triggered by user-opened files, not inbound network exploitation. ↗
- ·At time of advisory publication, the vulnerability was not publicly disclosed or actively exploited, and was rated 'Exploitation Less Likely' for both latest and older software releases. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Windows Runtime Remote Code Execution Vulnerability
cisa·2022-08-18·CVSS 7.8
CVE-2022-21971 [HIGH] CWE-824 Microsoft Windows Runtime Remote Code Execution Vulnerability
Vulnerability: Microsoft Windows Runtime Remote Code Execution Vulnerability
Affected: Microsoft Windows
Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21971; https://nvd.nist.gov/vuln/detail/CVE-2022-21971
Remediation Due Date: 2022-09-08
Microsoft
Windows Runtime Remote Code Execution Vulnerability
vendor_msrc·2022-02-08·CVSS 7.8
CVE-2022-21971 [HIGH] Windows Runtime Remote Code Execution Vulnerability
Windows Runtime Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally.
For example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on their computer.
Windows Remote Procedure Call Runtime: Windows Remote Procedure Call Runtime
Microsoft: Microsoft
GHSA
GHSA-58gj-2v59-wxcq: Windows Runtime Remote Code Execution Vulnerability
ghsa_unreviewed·2022-02-10
CVE-2022-21971 [HIGH] CWE-824 GHSA-58gj-2v59-wxcq: Windows Runtime Remote Code Execution Vulnerability
Windows Runtime Remote Code Execution Vulnerability.
VulnCheck
Microsoft Windows Runtime Remote Code Execution Vulnerability
vulncheck·2022·CVSS 7.8
CVE-2022-21971 [HIGH] CWE-824 Microsoft Windows Runtime Remote Code Execution Vulnerability
Microsoft Windows Runtime Remote Code Execution Vulnerability
Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/39981df7046c
Remediation Due: 2022-09-08
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-09
Published
2022-08-18
Added to CISA KEV
Exploited in the wild