CVE-2022-34725
published 2022-09-13CVE-2022-34725: Windows ALPC Elevation of Privilege Vulnerability Windows ALPC Elevation of Privilege Vulnerability
high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
5.38%
91.8th percentile
Windows ALPC Elevation of Privilege Vulnerability
Windows ALPC Elevation of Privilege Vulnerability
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19444 | 10.0.10240.19444 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5356 | 10.0.14393.5356 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3406 | 10.0.17763.3406 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3406 | 10.0.17763.3406 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2006 | 10.0.19042.2006 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.2006 | 10.0.19043.2006 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2006 | 10.0.19044.2006 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.978 | 10.0.22000.978 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20571 | 6.3.9600.20571 |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23865 | 6.2.9200.23865 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20571 | 6.3.9600.20571 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5356 | 10.0.14393.5356 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.3406 | 10.0.17763.3406 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.1006 | 10.0.20348.1006 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
cvelistv57.0HIGH
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-47fw-6h49-r836: Windows ALPC Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-09-14
CVE-2022-34725 [HIGH] CWE-362 GHSA-47fw-6h49-r836: Windows ALPC Elevation of Privilege Vulnerability
Windows ALPC Elevation of Privilege Vulnerability.
CVEList
Windows ALPC Elevation of Privilege Vulnerability
cvelistv5·2022-09-13·CVSS 7.0
CVE-2022-34725 [HIGH] Windows ALPC Elevation of Privilege Vulnerability
Windows ALPC Elevation of Privilege Vulnerability
Windows ALPC Elevation of Privilege Vulnerability
Microsoft
Windows ALPC Elevation of Privilege Vulnerability
vendor_msrc·2022-09-13·CVSS 7.0
CVE-2022-34725 [HIGH] Windows ALPC Elevation of Privilege Vulnerability
Windows ALPC Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
Windows ALPC: Windows ALPC
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5017315
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday for September 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-09-13·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for September 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for September 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing 64 vulnerabilities across the company’s hardware and software line, a sharp decline from the record number of issues Microsoft disclosed last month.
September's security update features five critical vulnerabilities, 10 fewer than were included in last month’s Patch Tuesday. There are two moderate-severity vulnerabilities in this release and a low-security issue that’s already been patched as a part of a recent Google Chromium update. The remainder is considered “important.”
The most serious vulnerability exists in several versions of Windows Server and Windows 10 that could allow an attacker to gain the ability to execute remote co
Talos
Microsoft Patch Tuesday for September 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-09-13·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for September 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing 64 vulnerabilities across the company’s hardware and software line, a sharp decline from the record number of issues Microsoft disclosed last month.
September's security update features five critical vulnerabilities, 10 fewer than were included in last month’s Patch Tuesday. There are two moderate-severity vulnerabilities in this release and a low-security issue that’s already been patched as a part of a recent Google Chromium update. The remainder is considered “important.”
The most serious vulnerability exists in several versions of Windows Server and Windows 10 that could allow an attacker to gain the ability to execute remote code (RCE) by sending a singular, specially crafted IPv6 packet to a Windows node where IPSec
2022-09-13
Published