CVE-2022-30202
published 2022-07-12CVE-2022-30202: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
PriorityP335high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
4.36%
90.2th percentile
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19360 | 10.0.10240.19360 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5246 | 10.0.14393.5246 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3165 | 10.0.17763.3165 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3165 | 10.0.17763.3165 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1826 | 10.0.19042.1826 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1826 | 10.0.19043.1826 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1826 | 10.0.19044.1826 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.795 | 10.0.22000.795 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.26022 | 6.1.7601.26022 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.26022 | 6.1.7601.26022 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20478 | 6.3.9600.20478 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26022 | 6.1.7601.26022 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21569 | 6.0.6003.21569 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23771 | 6.2.9200.23771 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20478 | 6.3.9600.20478 |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5246 | 10.0.14393.5246 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.3165 | 10.0.17763.3165 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2mv7-g8jg-j2fh: Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-07-13·CVSS 7.0
CVE-2022-22037 [HIGH] CWE-269 GHSA-2mv7-g8jg-j2fh: Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-30202, CVE-2022-30224.
GHSA
GHSA-9cr6-j4rm-w596: Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-07-13·CVSS 7.5
CVE-2022-30202 [HIGH] GHSA-9cr6-j4rm-w596: Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-22037, CVE-2022-30224.
GHSA
GHSA-v4fj-xpm7-phwr: Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-07-13·CVSS 7.5
CVE-2022-30224 [HIGH] CWE-269 GHSA-v4fj-xpm7-phwr: Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-22037, CVE-2022-30202.
Microsoft
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
vendor_msrc·2022-07-12·CVSS 7.0
CVE-2022-30202 [HIGH] Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Advanced Local Procedure Call: Windows Advanced Local Procedure Call
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-07-12·CVSS 8.1
[HIGH] Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing more than 80 vulnerabilities in the company’s various software, hardware and firmware offerings, including one that’s actively being exploited in the wild.
July's security update features three critical vulnerabilities, up from one last month, still lower than Microsoft’s average in a Patch Tuesday. All the other vulnerabilities fixed are considered “important.”
All three critical vulnerabilities allow remote code execution on Microsoft Windows Systems. Of these, Microsoft considers the exploitation of CVE-2022-22029 , CVE-2022-22038 and CVE-2022-22039 less likely to occur. CVE-2022-22029 could be exploited over the network by making an
Talos
Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-07-12·CVSS 8.1
[HIGH] Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing more than 80 vulnerabilities in the company’s various software, hardware and firmware offerings, including one that’s actively being exploited in the wild.
July's security update features three critical vulnerabilities, up from one last month, still lower than Microsoft’s average in a Patch Tuesday. All the other vulnerabilities fixed are considered “important.”
All three critical vulnerabilities allow remote code execution on Microsoft Windows Systems. Of these, Microsoft considers the exploitation of CVE-2022-22029, CVE-2022-22038 and CVE-2022-22039 less likely to occur. CVE-2022-22029 could be exploited over the network by making an unauthenticated, specially crafted call to a Network File System (NFS). However, accord
Zscaler
Zscaler found Windows security vulnerabilities | 07-12-2022
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler found Windows security vulnerabilities | 07-12-2022
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2022-07-12
Published