cbcvebase.
CVE-2022-22047
published 2022-07-12

CVE-2022-22047: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

PriorityP182high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-08-02
Exploited in the wild
EPSS
18.77%
97.0th percentile
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.1936010.0.10240.19360
microsoftwindows_10_1607< 10.0.14393.524610.0.14393.5246
microsoftwindows_10_1809< 10.0.17763.316510.0.17763.3165
microsoftwindows_10_20h2< 10.0.19042.182610.0.19042.1826
microsoftwindows_10_21h1< 10.0.19043.182610.0.19043.1826
microsoftwindows_10_21h2< 10.0.19044.182610.0.19044.1826
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.1936010.0.10240.19360
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.524610.0.14393.5246
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.316510.0.17763.3165
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.316510.0.17763.3165
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.182610.0.19042.1826
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.182610.0.19043.1826
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.182610.0.19044.1826
microsoftwindows_11_21h2< 10.0.22000.79510.0.22000.795
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.79510.0.22000.795
microsoftwindows_7>= 6.1.0 < 6.1.7601.260226.1.7601.26022
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.260226.1.7601.26022
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.204786.3.9600.20478
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.260226.1.7601.26022
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.215696.0.6003.21569
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.237716.2.9200.23771
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.204786.3.9600.20478
microsoftwindows_server_2016< 10.0.14393.524610.0.14393.5246

Detection & IOCsextracted from sources · hover to see the quote

hash9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
hash2915b3f8b703eb744fc54c81f4a9c67f
hashe4973db44081591e9bff5117946defbef6041397e56164f485cf8ec57b1d8934
hash93fefc3e88ffb78abb36365fa5cf857c
hashe12b6641d7e7e4da97a0ff8e1a0d4840c882569d47b8fab8fb187ac2b475636c
hasha087b2e6ec57b08c0d0750c60f96a74c
hashea500d77aabc3c9d440480002c3f1d2f2977a7f860f35260edda8a26406ca1c3
hash5741eadfc89a1352c61f1ff0a5c01c06
hash125e12c8045689bb2a5dcad6fa2644847156dec8b533ee8a3653b432f8fd5645
hash2c8ea737a232fd03ab80db672d50a17a
filenameVID001.exe
filenameLwssPlayer.scr
  • Talos has published multiple Snort rules to detect exploitation attempts of CVE-2022-22047; consult the Talos Patch Tuesday blog post for the specific rule IDs.
  • Successful exploitation results in code execution as SYSTEM; hunt for unexpected SYSTEM-level process creation originating from CSRSS (csrss.exe) child processes.
  • CVE-2022-22047 was weaponised by threat actor KNOTWEED (Denim Tsunami) to deploy the Subzero malware; detections for win.subzero should be prioritised alongside this CVE.
  • Check Point IPS signature 'Microsoft Windows Client/Server Runtime Subsystem Elevation of Privilege (CVE-2022-22047)' can be used as a detection reference for network-level coverage.
  • Microsoft confirmed active in-the-wild exploitation at time of patch release; treat any unpatched CSRSS process anomalies as high-priority incidents.
  • ·Exploitation requires local/physical access to the target machine; remote-only detection approaches will not cover the full attack surface.
  • ·The Talos Snort rule IDs for CVE-2022-22047 are not enumerated in the newsletter; analysts must retrieve them from the linked Patch Tuesday blog post.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.