CVE-2022-44673
published 2022-12-13CVE-2022-44673: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
PriorityP336high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
5.24%
91.6th percentile
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19624 | 10.0.10240.19624 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5582 | 10.0.14393.5582 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3770 | 10.0.17763.3770 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2364 | 10.0.19042.2364 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.2364 | 10.0.19043.2364 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.2364 | 10.0.19044.2364 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2364 | 10.0.19045.2364 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.26266 | 6.1.7601.26266 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20721 | 6.3.9600.20721 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21815 | 6.0.6003.21815 |
| msrc | windows_10_for_32-bit_systems | — | — |
| msrc | windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | windows_10_version_20h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_21h1_for_32-bit_systems | — | — |
| msrc | windows_10_version_21h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_22h2_for_32-bit_systems | — | — |
| msrc | windows_7_for_32-bit_systems_service_pack_1 | — | — |
| msrc | windows_8.1_for_32-bit_systems | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gjq9-gv86-9pf8: Windows Client Server Run-Time Subsystem (CSRSS) Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-12-13
CVE-2022-44673 [HIGH] GHSA-gjq9-gv86-9pf8: Windows Client Server Run-Time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-Time Subsystem (CSRSS) Elevation of Privilege Vulnerability.
Microsoft
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
vendor_msrc·2022-12-13·CVSS 7.0
CVE-2022-44673 [HIGH] Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
Client Server Run-time Subsystem (CSRSS): Client Server Run-time Subsystem (CSRSS)
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation
No detection rules found.
No public exploits indexed.
Checkpoint
19th December – Threat Intelligence Report
blogs_checkpoint·2022-12-20
CVE-2022-44673 19th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 19th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th December, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
Information of more than 80,000 security professionals and law enforcement officers is being offered for sale online, after the FBI’s information sharing portal InfraGard has been breached. The attacker has gained access to InfraGard after applying to join the platform impersonating a financial corporation’s CEO, then usi
Talos
Microsoft Patch Tuesday for December 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-12-13·CVSS 8.5
CVE-2022-41076 [HIGH] Microsoft Patch Tuesday for December 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 48 vulnerabilities. Of these vulnerabilities, 6 are classified as “Critical”, 41 are classified as “Important”, with the remaining vulnerability classified as “Moderate.”
One of the critical vulnerabilities, which Microsoft considers to be “more likely” to be exploited is CVE-2022-41076, a remote code execution (RCE) vulnerability in Windows PowerShell which could allow a previously authenticated attacker to escape the PowerShell Remoting Session Configuration and run unauthorized commands on compromised systems.
Another critical vulnerability, CVE-2022-41127, affects Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central. Successful exploitation could allow an attacker to execute code on Dynamic NAV server
Talos
Microsoft Patch Tuesday for December 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-12-13·CVSS 8.5
CVE-2022-41076 [HIGH] Microsoft Patch Tuesday for December 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for December 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 48 vulnerabilities. Of these vulnerabilities, 6 are classified as “Critical”, 41 are classified as “Important”, with the remaining vulnerability classified as “Moderate.”
One of the critical vulnerabilities, which Microsoft considers to be “more likely” to be exploited is CVE-2022-41076 , a remote code execution (RCE) vulnerability in Windows PowerShell which could allow a previously authenticated attacker to escape the PowerShell Remoting Session Configuration and run unauthorized commands on compromised systems.
Another critical vulnerability, CVE-2022-41127 , affects Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Ce
2022-12-13
Published