CVE-2022-41093
published 2022-11-09CVE-2022-41093: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
PriorityP338high7.8CVSS 3.1
AVLACHPRLUINSCCHIHAH
EPSS
0.29%
21.1th percentile
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19567 | 10.0.10240.19567 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2251 | 10.0.19042.2251 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.2251 | 10.0.19043.2251 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2251 | 10.0.19044.2251 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2251 | 10.0.19045.2251 |
| microsoft | windows_11 | — | — |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1219 | 10.0.22000.1219 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.819 | 10.0.22621.819 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20671 | 6.3.9600.20671 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20671 | 6.3.9600.20671 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.1249 | 10.0.20348.1249 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8rv7-9xg2-8mvc: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 7.8
CVE-2022-41100 [HIGH] CWE-362 GHSA-8rv7-9xg2-8mvc: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41045, CVE-2022-41093.
GHSA
GHSA-wc7p-3vcr-979v: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 7.8
CVE-2022-41093 [HIGH] CWE-362 GHSA-wc7p-3vcr-979v: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41045, CVE-2022-41100.
GHSA
GHSA-9p7f-fp2w-2p9p: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 7.8
CVE-2022-41045 [HIGH] CWE-362 GHSA-9p7f-fp2w-2p9p: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41093, CVE-2022-41100.
Microsoft
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
vendor_msrc·2022-11-08·CVSS 7.8
CVE-2022-41093 [HIGH] Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
This vulnerability could lead to a contained execution environment escape. Please refer to AppContainer Isolation for more information.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
A domain user could use this vulnerability to elevate privileges to SYSTEM assigned integrity level.
Windows Advanced Local Proced
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-09
Published