CVE-2022-21971
Memory Safety in Microsoft Windows 10 1809 ≤ 10.0.17763.2565
Raw vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HSummary
CVE-2022-21971 is a high-severity Access of Uninitialized Pointer (CWE-824) vulnerability in Microsoft Windows 10 1809. Its CVSS base score is 7.8 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked in the top 1% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2022-21971 is a remote code execution vulnerability in the Windows Runtime component, present across multiple versions of Microsoft Windows. It stems from access of an uninitialized pointer (CWE-824) and carries a CVSS 3.1 score of 7.8, reflecting local attack vector, low complexity, no required privileges, and required user interaction that nonetheless yields high impact on confidentiality, integrity, and availability.
An attacker with the ability to supply a malicious file or trigger specific local actions can exploit the flaw to execute arbitrary code in the context of the logged-on user, enabling full compromise of the affected system without additional authentication.
Microsoft security updates addressing the issue are detailed in the vendor advisory, while CISA includes CVE-2022-21971 in its catalog of known exploited vulnerabilities. The associated EPSS score has remained at a sustained high of 0.8779, indicating ongoing exploitation interest after public disclosure.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2022-27126
Vulnerability Data
Windows Runtime Remote Code Execution Vulnerability
- CWE(s)
- KEV Date Added
- 18 August 2022
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent uninitialized pointer bugs via coding standards, analysis, and reviews, but eliminating this single weakness only partially fulfills the broader control.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect uninitialized pointer usage before release.
Secure development life cycle mandates practices that reduce uninitialized pointer defects.
Application security requirements can specify pointer initialization rules.
Secure architecture principles discourage unsafe pointer handling.
Secure coding standards directly prohibit use of uninitialized pointers.