Important CVSS 7.8 EPSS 0.01667 ⚠️ Exploited in the wild 🔬 Patch diffed 2022-10 archive

Executive Summary

None

Overview

7.8
CVSS HIGH
Important
MS Severity
Exploited
MS Exploit Status
Exploitation Detected
MS Exploit Likelihood
Category Elevation of Privilege
Released Oct 11 2022
Last Updated Oct 11 2022
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.01667 — 0.74671 percentile
NVD CVSS 7.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.8

EPSS Score

0.01667
probability of exploitation in the next 30 days
0.74671 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

26 affected products
Product KB Article Severity Impact Restart Required
Windows 10 for 32-bit Systems 5018425 (Security Update) Important Elevation of Privilege Yes
Windows 10 for x64-based Systems 5018425 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for 32-bit Systems 5018411 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for x64-based Systems 5018411 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for 32-bit Systems 5018419 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for ARM64-based Systems 5018419 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for x64-based Systems 5018419 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 20H2 for 32-bit Systems 5018410 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 20H2 for ARM64-based Systems 5018410 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H1 for 32-bit Systems 5018410 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H1 for ARM64-based Systems 5018410 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H1 for x64-based Systems 5018410 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for 32-bit Systems 5018410 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for ARM64-based Systems 5018410 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for x64-based Systems 5018410 (Security Update) Important Elevation of Privilege Yes
Windows 11 version 21H2 for ARM64-based Systems 5018418 (Security Update) Important Elevation of Privilege Yes
Windows 11 version 21H2 for x64-based Systems 5018418 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 22H2 for ARM64-based Systems 5018427 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 22H2 for x64-based Systems 5018427 (Security Update) Important Elevation of Privilege Yes
Windows 7 for 32-bit Systems Service Pack 1 5018454 (Monthly Rollup) 5018479 (Security Only) Important Elevation of Privilege 5017361 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26174 Yes 5018454 5018479 Windows 7 for x64-based Systems Service Pack 1 5018454 (Monthly Rollup) 5018479 (Security Only) Important Elevation of Privilege 5017361 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26174 Yes 5018454 5018479 Windows 8.1 for 32-bit systems 5018474 (Monthly Rollup) 5018476 (Security Only) Important Elevation of Privilege 5017367 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20625 Yes 5018474 5018476 Windows 8.1 for x64-based systems 5018474 (Monthly Rollup) 5018476 (Security Only) Important Elevation of Privilege 5017367 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20625 Yes 5018474 5018476 Windows RT 8.1 5018474 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2008 for 32-bit Systems Service Pack 2 5018450 (Monthly Rollup) 5018446 (Security Only) Important Elevation of Privilege 5017358 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21721 Yes 5018450 5018446 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5018450 (Monthly Rollup) 5018446 (Security Only) Important Elevation of Privilege 5017358 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21721 Yes 5018450 5018446 Windows Server 2008 for x64-based Systems Service Pack 2 5018450 (Monthly Rollup) 5018446 (Security Only) Important Elevation of Privilege 5017358 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21721 Yes 5018450 5018446 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5018450 (Monthly Rollup) 5018446 (Security Only) Important Elevation of Privilege 5017358 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21721 Yes 5018450 5018446 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5018454 (Monthly Rollup) 5018479 (Security Only) Important Elevation of Privilege 5017361 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26174 Yes 5018454 5018479 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5018454 (Monthly Rollup) 5018479 (Security Only) Important Elevation of Privilege 5017361 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26174 Yes 5018454 5018479 Windows Server 2012 5018457 (Monthly Rollup) 5018478 (Security Only) Important Elevation of Privilege 5017370 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.2.9200.23920 Yes 5018457 5018478 Windows Server 2012 (Server Core installation) 5018457 (Monthly Rollup) 5018478 (Security Only) Important Elevation of Privilege 5017370 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.2.9200.23920 Yes 5018457 5018478 Windows Server 2012 R2 5018474 (Monthly Rollup) 5018476 (Security Only) Important Elevation of Privilege 5017367 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20625 Yes 5018474 5018476 Windows Server 2012 R2 (Server Core installation) 5018474 (Monthly Rollup) 5018476 (Security Only) Important Elevation of Privilege 5017367 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20625 Yes 5018474 5018476 Windows Server 2016 5018411 (Security Update) Important Elevation of Privilege Yes
Windows Server 2016 (Server Core installation) 5018411 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 5018419 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 (Server Core installation) 5018419 (Security Update) Important Elevation of Privilege Yes
Windows Server 2022 5018421 (Security Update) Important Elevation of Privilege Yes
Windows Server 2022 (Server Core installation) 5018421 (Security Update) Important Elevation of Privilege Yes

Patches

8 patches
Article Type Restart
5018425 Security Update Yes
5018411 Security Update Yes
5018419 Security Update Yes
5018410 Security Update Yes
5018418 Security Update Yes
5018427 Security Update Yes
5018474 Monthly Rollup Yes
5018421 Security Update Yes

Patch Diff

ghidriff · es.dll (KB5018410)

Exploited in-the-wild type confusion (CWE-843) in the Windows COM+ Event System service es.dll -> local EoP (LOCAL SERVICE + SeImpersonate -> SYSTEM). Any normal (non-sandboxed) user can CoCreateInstance(EventSystemTier2, CLSID 1be1f766-5536-11d1-b726-00c04fb926af), call IEventSystemTier2::CreateSubscription(name, TRUE) to get an IEventSubscriptionTier2, then IEventSubscriptionTier2::Store, reaching CSubscription2::Store -> InMemoryRegRow::PutPropertyBag(Names, Values). PutPropertyBag treats Values as a vector of PROPVARIANTs (Values.capropvar.pElems) WITHOUT checking the PROPVARIANT vt field. Because PROPVARIANT is a union, an attacker passes a VT_BLOB whose fields alias CAPROPVARIANT (BLOB.cbSize<->cElems, BLOB.pBlobData<->pElems); the COM runtime validates the blob length but not that the bytes are real PROPVARIANTs, so the attacker's byte array is interpreted as a PROPVARIANT[] with a fake VT_UNKNOWN holding a bogus pointer. PropVariantCopy then dereferences that pointer for its vtable and calls IUnknown::AddRef - a controlled deref/vcall. IN-HOUSE ghidriff (Sep -> Oct 11 2022) confirms the fix: a new ValidatePropertyBag function (plus helper IsEmptyOrBSTR) is added and called at the start of InMemoryRegRow::PutPropertyBag (68% match) and RegistryRegRow::PutPropertyBag (99% match); it requires Names.vt==(VT_VECTOR|VT_LPWSTR), Values.vt==(VT_VECTOR|VT_VARIANT) and matching cElems, else E_INVALIDARG - rejecting the VT_BLOB alias before any dereference. Unconditional fix. RCA: James Forshaw / Google Project Zero (0day ITW).

Pre-patch version 2001.12.10941.16384 (Sep 2022) Download
Post-patch version 2001.12.10941.16384 (Oct 2022) Download
Function Address Change Note
ValidatePropertyBag added added (type/size validation) New function: returns S_OK only if Names.vt==(VT_VECTOR|VT_LPWSTR), Values.vt==(VT_VECTOR|VT_VARIANT), and Names.calpwstr.cElems==Values.capropvar.cElems; otherwise E_INVALIDARG. Rejects the VT_BLOB-aliased-to-CAPROPVARIANT type confusion.
InMemoryRegRow::PutPropertyBag 68% match code (calls ValidatePropertyBag first) The in-memory property-bag path (transient subscription) - the exploited sink. Post-patch validates the two PROPVARIANTs via ValidatePropertyBag before iterating Values.capropvar.pElems, so a faked array is refused.
RegistryRegRow::PutPropertyBag 99% match code (calls ValidatePropertyBag first) Registry-backed property-bag path; gains the same ValidatePropertyBag call. P0 notes it may retain a lesser info-disclosure concern but the type confusion is closed.
IsEmptyOrBSTR added added (helper) Small helper added alongside the validation hardening.
View full diff report View RCA report

Attack Path

A VT_BLOB is aliased to a PROPVARIANT array, faking a VT_UNKNOWN pointer that the COM+ service dereferences

Attack path for CVE-2022-41033 A VT_BLOB is aliased to a PROPVARIANT array, faking a VT_UNKNOWN pointer that the COM+ service dereferences 01 — ENTRY Normal user instantiates the COM+ EventSystemTier2 object (auto-starts the service) CoCreateInstance(EventSystemTier2, CLSID 1be1f766-...) is allowed for Everyone/INTERACTIVE (not sandboxed processes). The COM+ Event System service runs as LOCAL SERVICE with SeImpersonatePrivilege. 02 — CONTROLLED INPUT Creates a transient subscription and calls IEventSubscriptionTier2::Store CreateSubscription(name, TRUE) returns an IEventSubscriptionTier2 backed by an in-memory property bag; Store passes Names and Values PROPVARIANT vectors, reaching CSubscription2::Store -> InMemoryRegRow::PutPropertyBag. 03 — PATH PutPropertyBag treats Values as a PROPVARIANT array and PropVariantCopy's each element It reads Values.capropvar.pElems[i] and calls PropVariantCopy without checking the vt field. 04 — MISSING CHECK A VT_BLOB aliases CAPROPVARIANT, so attacker bytes become a fake PROPVARIANT[] with a bogus VT_UNKNOWN pointer PROPVARIANT is a union: BLOB.cbSize<->cElems, BLOB.pBlobData<->pElems. The COM runtime checks the blob length but not that its bytes are valid variants (CWE-843). 05 — PRIMITIVE Controlled pointer dereference / AddRef vcall in LOCAL SERVICE -> SYSTEM PropVariantCopy dereferences the fake VT_UNKNOWN pointer for its vtable and calls IUnknown::AddRef - a controlled deref/virtual call turned into code execution in the LOCAL SERVICE process, then SeImpersonate -> SYSTEM. Exploited in the wild. The Oct 2022 fix adds ValidatePropertyBag to reject mismatched variant types.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Known Exploits

Acknowledgments

Anonymous