CVE-2022-41086
published 2022-11-09CVE-2022-41086: Windows Group Policy Elevation of Privilege Vulnerability
PriorityP426medium6.4CVSS 3.1
AVLACHPRHUINSUCHIHAH
EPSS
0.25%
16.4th percentile
Windows Group Policy Elevation of Privilege Vulnerability
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19567 | 10.0.10240.19567 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2251 | 10.0.19042.2251 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.2251 | 10.0.19043.2251 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2251 | 10.0.19044.2251 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2251 | 10.0.19045.2251 |
| microsoft | windows_11 | — | — |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1219 | 10.0.22000.1219 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.819 | 10.0.22621.819 |
| microsoft | windows_7 | — | — |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.26221 | 6.1.7601.26221 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.26221 | 6.1.7601.26221 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20671 | 6.3.9600.20671 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26221 | 6.1.7601.26221 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21768 | 6.0.6003.21768 |
| microsoft | windows_server_2012 | — | — |
CVSS provenance
nvdv3.16.4MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_msrc6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2346-6pqf-j299: Windows Group Policy Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 7.8
CVE-2022-41086 [HIGH] CWE-362 GHSA-2346-6pqf-j299: Windows Group Policy Elevation of Privilege Vulnerability
Windows Group Policy Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37992.
GHSA
GHSA-x82j-4gxg-pv7v: Windows Group Policy Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 6.4
CVE-2022-37992 [MEDIUM] GHSA-x82j-4gxg-pv7v: Windows Group Policy Elevation of Privilege Vulnerability
Windows Group Policy Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41086.
Microsoft
Windows Group Policy Elevation of Privilege Vulnerability
vendor_msrc·2022-11-08·CVSS 6.4
CVE-2022-41086 [MEDIUM] Windows Group Policy Elevation of Privilege Vulnerability
Windows Group Policy Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could gain domain administrator privileges.
FAQ: According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires the attacker to have privileges to create Group Policy Templates. As is best practice, regular validation and audits of administrative groups should be conducted.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race conditio
No detection rules found.
No public exploits indexed.
2022-11-09
Published