CVE-2022-35841
published 2022-09-13CVE-2022-35841: Windows Enterprise App Management Service Remote Code Execution Vulnerability
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.76%
84.6th percentile
Windows Enterprise App Management Service Remote Code Execution Vulnerability
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19444 | 10.0.10240.19444 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5356 | 10.0.14393.5356 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3406 | 10.0.17763.3406 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3406 | 10.0.17763.3406 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2006 | 10.0.19042.2006 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.2006 | 10.0.19043.2006 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2006 | 10.0.19044.2006 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.978 | 10.0.22000.978 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5356 | 10.0.14393.5356 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.3406 | 10.0.17763.3406 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.1006 | 10.0.20348.1006 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The attack vector involves the Enterprise App Management service exposing a COM class that an authenticated attacker can abuse to install arbitrary SYSTEM services running with SYSTEM privileges. ↗
- ·Exploitation requires authentication; unauthenticated remote exploitation is not possible. Exploit status is publicly disclosed: No, and exploited in the wild: No at time of publication. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Enterprise App Management Service Remote Code Execution Vulnerability
vendor_msrc·2022-09-13·CVSS 8.8
CVE-2022-35841 [HIGH] Windows Enterprise App Management Service Remote Code Execution Vulnerability
Windows Enterprise App Management Service Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
The Enterprise App Management service exposes a COM class that could allow an authenticated attacker to install arbitrary SYSTEM services that run with SYSTEM privileges, which could result in remote code execution.
Windows Enterprise App Management: Windows Enterprise App Management
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5017315
Reference: https://support.microsoft.com/help/5017315
Re
GHSA
GHSA-9v3h-f742-f5hh: Windows Enterprise App Management Service Remote Code Execution Vulnerability
ghsa_unreviewed·2022-09-14
CVE-2022-35841 [HIGH] CWE-269 GHSA-9v3h-f742-f5hh: Windows Enterprise App Management Service Remote Code Execution Vulnerability
Windows Enterprise App Management Service Remote Code Execution Vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-13
Published