CVE-2022-41033
published 2022-10-11CVE-2022-41033: Windows COM+ Event System Service Elevation of Privilege Vulnerability
PriorityP180high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-11-01
Exploited in the wild
EPSS
1.76%
75.5th percentile
Windows COM+ Event System Service Elevation of Privilege Vulnerability
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19507 | 10.0.10240.19507 |
| microsoft | windows_10_1607 | < 10.0.14393.5427 | 10.0.14393.5427 |
| microsoft | windows_10_1809 | < 10.0.17763.3532 | 10.0.17763.3532 |
| microsoft | windows_10_20h2 | < 10.0.19042.2130 | 10.0.19042.2130 |
| microsoft | windows_10_21h1 | < 10.0.19043.2130 | 10.0.19043.2130 |
| microsoft | windows_10_21h2 | < 10.0.19044.2130 | 10.0.19044.2130 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19507 | 10.0.10240.19507 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5427 | 10.0.14393.5427 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3532 | 10.0.17763.3532 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3532 | 10.0.17763.3532 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2130 | 10.0.19042.2130 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.2130 | 10.0.19043.2130 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2130 | 10.0.19044.2130 |
| microsoft | windows_11_21h2 | < 10.0.22000.1098 | 10.0.22000.1098 |
| microsoft | windows_11_22h2 | < 10.0.22621.674 | 10.0.22621.674 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1098 | 10.0.22000.1098 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.674 | 10.0.22621.674 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.26174 | 6.1.7601.26174 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.26174 | 6.1.7601.26174 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20625 | 6.3.9600.20625 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26174 | 6.1.7601.26174 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21721 | 6.0.6003.21721 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23920 | 6.2.9200.23920 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-41033 is a local privilege escalation in the Windows COM+ Event System Service; monitor for unexpected SYSTEM-level process creation originating from lower-privileged user sessions, which may indicate exploitation of this service. ↗
- →Monitor the Windows COM+ Event System Service (EventSystem) for anomalous behavior; successful exploitation grants full SYSTEM privileges, so alert on any process running as SYSTEM that was spawned from a non-SYSTEM parent in the context of this service. ↗
- →CVE-2022-41033 is confirmed actively exploited in the wild (Exploitation Detected on latest software release); treat it as high-priority for detection and patching despite its relatively lower CVSS score. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qjvf-mwxj-x748: Windows COM+ Event System Service Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-10-12
CVE-2022-41033 [HIGH] CWE-843 GHSA-qjvf-mwxj-x748: Windows COM+ Event System Service Elevation of Privilege Vulnerability
Windows COM+ Event System Service Elevation of Privilege Vulnerability.
VulnCheck
Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability
vulncheck·2022·CVSS 7.8
CVE-2022-41033 [HIGH] CWE-843 Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability
Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability
Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2022-Oct; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://raw.githubusercontent.com/blackorbird/APT_REPORT/master/summary/2023/360_APT_Annual_Research_Report_2022.pdf
Remediation Due: 2022-11-01
Project0
Project Zero RCA: CVE-2022-41033: Type confusion in Windows COM+ Event System Service
project_zero·CVSS 7.8
CVE-2022-41033 [HIGH] Project Zero RCA: CVE-2022-41033: Type confusion in Windows COM+ Event System Service
# CVE-2022-41033: Type confusion in Windows COM+ Event System Service
*James Forshaw, Google Project Zero*
## The Basics
**Disclosure Date:** 11 October 2022
**Product:** Microsoft Windows
**Advisory:**
* Security bulletin: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41033
**Affected Versions:** Windows 8.1 through 11 and Windows Server 2012 R2 through 2022, prior to the October 2022 patches. Likely affects versions of Windows prior to 8.1, but that is not acknowledged by the vendor.
**First Patched Version:** Windows 8.1 through 11 and Windows Server 2012 R2 through 2022, prior to the October 2022 patches.
**Issue/Bug Report:** N/A
**Patch CL:** N/A
**Bug-Introducing CL:** N/A
**Reporter(s):** Anonymous
## The Code
**Proof-of-concept:**
```
#include
#inclu
Microsoft
Windows COM+ Event System Service Elevation of Privilege Vulnerability
vendor_msrc·2022-10-11·CVSS 7.8
CVE-2022-41033 [HIGH] Windows COM+ Event System Service Elevation of Privilege Vulnerability
Windows COM+ Event System Service Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows COM+ Event System Service: Windows COM+ Event System Service
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:Yes;Latest Software Release:Exploitation Detected;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5018419
Reference: https://support.microsoft.com/help/5018419
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5018410
Reference: ht
CISA
Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability
cisa·2022-10-11·CVSS 7.8
CVE-2022-41033 [HIGH] CWE-843 Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability
Affected: Microsoft Windows COM+ Event System Service
Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41033; https://nvd.nist.gov/vuln/detail/CVE-2022-41033
Remediation Due Date: 2022-11-01
No detection rules found.
No public exploits indexed.
Krebs
Microsoft Patch Tuesday, October 2022 Edition
blogs_krebs·2022-10-12·CVSS 10.0
CVE-2022-41033 [CRITICAL] Microsoft Patch Tuesday, October 2022 Edition
Microsoft today released updates to fix at least 85 security holes in its Windows operating systems and related software, including a new zero-day vulnerability in all supported versions of Windows that is being actively exploited. However, noticeably absent from this month’s Patch Tuesday are any updates to address a pair of zero-day flaws being exploited this past month in Microsoft Exchange Server.
The new zero-day flaw– CVE-2022-41033 — is an “elevation of privilege” bug in the Windows COM+ event service, which provides system notifications when users logon or logoff. Microsoft says the flaw is being actively exploited, and that it was reported by an anonymous individual.
“Despite its relatively low score in comparison to other vulnerabilities patched today, this one should be at the
Krebs
Microsoft Patch Tuesday, October 2022 Edition
blogs_krebs·2022-10-11·CVSS 10.0
CVE-2022-41033 [CRITICAL] Microsoft Patch Tuesday, October 2022 Edition
Microsoft today released updates to fix at least 85 security holes in its Windows operating systems and related software, including a new zero-day vulnerability in all supported versions of Windows that is being actively exploited. However, noticeably absent from this month’s Patch Tuesday are any updates to address a pair of zero-day flaws being exploited this past month in Microsoft Exchange Server .
The new zero-day flaw– CVE-2022-41033 — is an “elevation of privilege” bug in the Windows COM+ event service, which provides system notifications when users logon or logoff. Microsoft says the flaw is being actively exploited, and that it was reported by an anonymous individual.
“Despite its relatively low score in comparison to other vulnerabilities patched today, this one should be at th
Qualys
October 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities With 13 Critical, Plus 12 Microsoft Edge (Chromium-Based); Adobe Releases 4 Advisories, 29 Vulnerabilities With 17 Critical. | Qualys
blogs_qualys·2022-10-11·CVSS 7.8
[HIGH] October 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities With 13 Critical, Plus 12 Microsoft Edge (Chromium-Based); Adobe Releases 4 Advisories, 29 Vulnerabilities With 17 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- Microsoft Exchange ProxyNotShell Zero-Days Not Yet Addressed (QID 50122)
- The October 2022 Microsoft Vulnerabilities Are Classified As Follows:
- Two Zero-Day Vulnerabilities Addressed
- Microsoft Critical Vulnerability Highlights
- Microsoft Release Summary
- Microsoft Edge | Last But Not Least
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Qualys Threat Research Blog Posts
- Qualys Threat Protection High-Rated Advisories
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
- Rapid Response With Patch Management (PM)
- EXECUTE Mitigation Using Custom Assessment and Remediation (CAR)
- EVALUATE Vendor-Suggested Mitigation With Policy Compliance (PC)
- This Month
Qualys
October 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities With 13 Critical, Plus 12 Microsoft Edge (Chromium-Based); Adobe Releases 4 Advisories, 29 Vulnerabilities With 17 Critical.
blogs_qualys·2022-10-11·CVSS 7.8
[HIGH] October 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities With 13 Critical, Plus 12 Microsoft Edge (Chromium-Based); Adobe Releases 4 Advisories, 29 Vulnerabilities With 17 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
Microsoft Exchange ProxyNotShell Zero-Days Not Yet Addressed (QID 50122)
The October 2022 Microsoft Vulnerabilities Are Classified As Follows:
Two Zero-Day Vulnerabilities Addressed
Microsoft Critical Vulnerability Highlights
Microsoft Release Summary
Microsoft Edge | Last But Not Least
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Qualys Threat Research Blog Posts
Qualys Threat Protection High-Rated Advisories
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
Rapid Response With Patch Management (PM)
EXECUTE Mitigation Using Custom Assessment and Remediation (CAR)
EVALUATE Vendor-Suggested Mitigation With Policy Compliance (PC)
This Month in Vulnerabilities
Tenable
Microsoft’s October 2022 Patch Tuesday Addresses 84 CVEs (CVE-2022-41033)
blogs_tenable·2022-10-11·CVSS 7.8
[HIGH] Microsoft’s October 2022 Patch Tuesday Addresses 84 CVEs (CVE-2022-41033)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Crowdstrike
October Patch Tuesday 2022: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] October Patch Tuesday 2022: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
October Patch Tuesday 2022: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] October Patch Tuesday 2022: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2022-10-11
Published
2022-10-11
Added to CISA KEV
Exploited in the wild