CVE-2022-24487
published 2022-04-15CVE-2022-24487: Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.09%
79.5th percentile
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5066 | 10.0.14393.5066 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2803 | 10.0.17763.2803 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2803 | 10.0.17763.2803 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2212 | 10.0.18363.2212 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1645 | 10.0.19042.1645 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1645 | 10.0.19043.1645 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1645 | 10.0.19044.1645 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.613 | 10.0.22000.613 |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5066 | 10.0.14393.5066 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.2803 | 10.0.17763.2803 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.643 | 10.0.20348.643 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1645 | 10.0.19042.1645 |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
| msrc | windows_10_version_21h2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attacker must be a local user with a smart card OR already logged on remotely via RDP to the target machine before exploitation can occur. ↗
- →Exploitation vector is a user-mode application sending specially crafted malicious credentials to LSASS. Monitor for anomalous user-mode processes making unusual credential-related calls or IPC to lsass.exe. ↗
- ·Exploitation is rated 'Less Likely' for both latest and older software releases, and has not been publicly disclosed or observed in the wild as of advisory publication. ↗
- ·Customer action (patching) is required; affected component is Windows LSASS. Relevant KBs include 5012647, 5012591, 5012599, 5012604, 5012592, and 5012596. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q27v-9rwf-3cwc: Windows Local Security Authority (LSA) Remote Code Execution Vulnerability
ghsa_unreviewed·2022-04-16
CVE-2022-24487 [HIGH] GHSA-q27v-9rwf-3cwc: Windows Local Security Authority (LSA) Remote Code Execution Vulnerability
Windows Local Security Authority (LSA) Remote Code Execution Vulnerability.
Microsoft
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
vendor_msrc·2022-04-12·CVSS 8.8
CVE-2022-24487 [HIGH] Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
In order to exploit this vulnerability the attacker is required to be a local user with a smart card or already logged on remotely through RDP to the remote machine. The authorized attacker could then exploit this Windows LSASS vulnerability by sending, from a user mode application, specially crafted malicious credentials directed at the Windows machine, which could lead to remote code execution.
Windows Local Security Authority Subsystem Service (LSASS): Windows Local Security Authority Subsystem Service (LSASS)
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-15
Published