LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-21882: Microsoft Win32k Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 4, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Feb 18, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-21882 to its Known Exploited Vulnerabilities catalog on Feb 4, 2022, with a federal patch deadline of Feb 18, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

CVE-2022-21882 is a privilege escalation vulnerability in Microsoft Win32k, the Windows kernel-mode graphics and window-management component. An attacker who already has a foothold on a system could abuse it to gain higher privileges. Because Win32k is present on essentially every Windows endpoint and server, successful exploitation can turn a limited compromise into full system control, which is why defenders treat it as a high-priority item to inventory and patch.

Public detail on exact attack mechanics is limited; CISA describes an unspecified vulnerability that allows privilege escalation. Confirm all version, patch, and configuration specifics directly against the Microsoft advisory for this CVE.

How it works

The weakness is classified as CWE-787 (out-of-bounds write). In kernel components such as Win32k, an out-of-bounds write occurs when code writes data past the end or before the beginning of an intended buffer. That corruption can alter critical kernel structures or function pointers.

An attacker who can already run code at a lower privilege level would trigger the flawed path—typically by supplying crafted input that reaches the vulnerable Win32k routine. The resulting memory corruption is then leveraged to elevate the attacker’s token or execute code in a more privileged context. Exact trigger conditions and exploit primitives are not detailed in the supplied facts; treat any public proof-of-concept claims with caution and validate against the vendor advisory.

Am I affected? How to find it in your systems

Win32k ships as part of the Windows operating system itself and therefore runs on workstations, laptops, and servers that use the Windows GUI subsystem. It is not an optional add-on; virtually every Windows installation that has not been deliberately stripped of graphical components includes it.

Because the facts supply no definitive version range, treat every Windows host as potentially affected until you have confirmed the presence of the vendor fix.

How to remediate

The primary remediation is to apply the security update Microsoft released for this vulnerability. Follow the installation guidance and reboot requirements stated in the official advisory. CISA’s required action is simply to apply updates per vendor instructions.

If you can't patch immediately

When immediate patching is impossible, reduce the likelihood that an attacker can reach the vulnerable code path and limit the damage if they do.

These measures buy time but do not eliminate the vulnerability—schedule the official update as soon as operationally possible.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are frequently used after initial access to dump credentials, disable security tools, or deploy further payloads. The supplied facts do not document ransomware use specifically for CVE-2022-21882, yet any successful elevation still expands an attacker’s reach. If you suspect compromise, follow your incident-response plan: isolate affected hosts, preserve volatile evidence, and rotate credentials that may have been exposed. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Win32k
WeaknessCWE-787
Added to CISA KEVFeb 4, 2022
Federal patch deadlineFeb 18, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities