CVE-2022-41125
Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability
CVSS
7.8
High
EPSS
3.0%
p87
KEV
YES
Nov 8, 2022
Exploit Today
76
0-100
Published: Nov 9, 2022 · Last modified: Aug 10, 2026 · CWE-787
Product
Microsoft / Windows
Vulnerability
Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability
Added to KEV
Nov 8, 2022
Remediate by
Dec 9, 2022
Known ransomware use
No
Summary description
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
Required action
Apply updates per vendor instructions.
Notes
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41125; https://nvd.nist.gov/vuln/detail/CVE-2022-41125
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability