CVE-2022-21882 is a Microsoft Windows Win32k elevation-of-privilege vulnerability. Microsoft patched the issue in January 2022. It was reportedly a patch bypass variant of CVE-2021-1732 and was confirmed exploited in the wild before its addition to CISA’s Known Exploited Vulnerabilities catalog.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module implementing a local privilege escalation exploit for the Win32k ConsoleControl Offset Confusion vulnerability (CVE-2022-21882), which is a patch bypass of CVE-2021-1732. The exploit targets Windows 10 (versions 1803-21H2 x64), Windows 11 21H2, Server 2019, and Server 2022. The module is written in Ruby and leverages Metasploit's post-exploitation and reflective DLL injection capabilities. The exploit works by manipulating the WndExtra field of a window object in the Windows kernel, leading to an out-of-bounds write and privilege escalation to SYSTEM. The payload is customizable and injected as a DLL, typically resulting in a privileged Meterpreter shell. The module includes checks for target compatibility and architecture, and will fail gracefully if the session is already elevated or if the architecture is unsupported. The only fingerprintable endpoint is the DLL file used for injection. The repository is weaponized, as it is part of the Metasploit framework and allows for easy payload customization and deployment.
This repository contains a working local privilege escalation exploit for CVE-2022-21882, targeting the Win32k Elevation of Privilege vulnerability in Microsoft Windows 10 21H2. The main file, CVE-2022-21882.cpp, is a C++ source code implementing the exploit logic. It manipulates Windows kernel structures via user-mode callbacks and window class extra bytes to achieve arbitrary kernel read/write, ultimately stealing the SYSTEM process token and spawning a SYSTEM-level command shell (cmd.exe). The exploit requires local code execution privileges and is only applicable to Windows 10 21H2. The repository also includes a brief README describing the vulnerability and its target platform. No network endpoints are present; all actions are performed locally. The exploit is operational and provides a SYSTEM shell if successful.
This repository is a proof-of-concept (PoC) exploit for CVE-2022-21882, a Windows Win32k privilege escalation vulnerability. The main exploit code is in 'cve-2022-21882-poc/cve-2022-21882-poc.cpp', which is a C++ file designed to be built with Visual Studio (project files are included). The exploit works by manipulating Windows kernel structures via user-mode callbacks and window class extra bytes, ultimately stealing the SYSTEM process token and assigning it to the current process. Upon success, it spawns a SYSTEM-level command shell (cmd.exe). The attack vector is local, requiring code execution on the target system. The repository is structured as a typical Visual Studio C++ project, with build logs and configuration files included. No network endpoints or remote attack surfaces are present; the exploit is strictly for local privilege escalation on vulnerable Windows systems.
This repository is a proof-of-concept (POC) exploit for CVE-2022-21882, a local privilege escalation (LPE) vulnerability in the Windows kernel (win32k.sys), which is a bypass for the earlier CVE-2021-1732. The exploit is specifically tested on Windows 10 20H2 build 19042.1415. The repository contains Visual Studio project files and a single code file, 'shellcode.asm', which implements a syscall wrapper for NtUserMessageCall (syscall number 0x1007). This shellcode is likely used to trigger the vulnerable code path in the Windows kernel. There are no network or remote attack vectors; the exploit is purely local and requires code execution on the target system. The README provides a brief description and references a demonstration GIF and a tweet for further context. No detection scripts or fake code are present; this is a genuine exploit POC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Win32k elevation-of-privilege vulnerability in Windows 10 that, despite a lower CVSS score, has very high exploitation likelihood, confirmed in-the-wild exploitation, KEV inclusion, and public PoC availability.
Previously patched Windows Win32k elevation of privilege vulnerability referenced as a patch bypass for an earlier Win32k zero-day.
Referenced prior Windows vulnerability with public exploit code, cited as related material for exploitation techniques.
A Windows win32k vulnerability exploited in the wild in 2022, which is a variant of a previously patched 2021 in-the-wild vulnerability (CVE-2021-1732).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.