LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-41125: Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 9, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-41125 to its Known Exploited Vulnerabilities catalog on Nov 8, 2022, with a federal patch deadline of Dec 9, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.

CVE-2022-41125 is a privilege-escalation vulnerability in the Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service. An attacker who can already run code on a system may abuse the flaw to obtain SYSTEM-level privileges. That level of access lets an adversary disable security tools, install persistence, move laterally, or access sensitive data, so the issue matters for any organization that runs Windows endpoints or servers.

Public detail is limited to the CISA summary and the assigned weakness class; exact affected builds, exploit mechanics, and scoring must be confirmed against the Microsoft advisory.

How it works

The vulnerability is classified as CWE-787 (Out-of-bounds Write). In the CNG Key Isolation Service, which handles cryptographic key material in a privileged context, an out-of-bounds write can corrupt memory that the service uses. An attacker who already has a foothold on the host can trigger this condition to elevate from a lower-privileged process to SYSTEM. The CISA summary describes the outcome as an unspecified vulnerability that allows SYSTEM-level privileges; no further exploit details are provided in the available facts, so defenders should treat any local code execution as a potential path to full host compromise until the vendor advisory is reviewed.

Am I affected? How to find it in your systems

The issue affects Microsoft Windows systems that include the CNG Key Isolation Service (commonly present on modern client and server editions). Inventory all Windows hosts via asset-management tools, Active Directory queries, or endpoint-management platforms. Confirm whether the service is running and identify the exact OS build and patch level; compare those values only against the versions listed in the Microsoft security update for CVE-2022-41125.

How to remediate

Apply the Microsoft security update that addresses CVE-2022-41125 as soon as it can be tested and deployed. CISA’s required action is simply to apply updates per vendor instructions. After patching, verify the update is present on every host and restart any services or systems that the advisory indicates require a reboot.

If you can't patch immediately

Until the vendor update can be installed, reduce the attack surface and increase detection around local privilege escalation.

If your data may have been exposed

Actively exploited local privilege-escalation vulnerabilities frequently serve as a stepping stone to broader compromise and data theft. Known ransomware use of this CVE is not documented in the provided facts. If you suspect the vulnerability was used in your environment, treat the host as compromised, isolate it, collect forensic evidence, and rotate any credentials or secrets that may have been accessible to SYSTEM. As a quick check for previously leaked credentials, you can run a free exposure scan of your email addresses against known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-787
Added to CISA KEVNov 8, 2022
Federal patch deadlineDec 9, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities