First published: Tue Jan 11 2022(Updated: )
Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Visual Studio 2017 | >=15.0<15.9.44 | |
Microsoft Visual Studio 2019 | >=16.0<16.7.25 | |
Microsoft Visual Studio 2019 | >=16.8<16.9.17 | |
Microsoft Windows 10 | <10.0.10240.19177 | |
Microsoft Windows 10 | <10.0.10240.19177 | |
Microsoft Windows 10 1607 | <10.0.14393.4886 | |
Microsoft Windows 10 1607 | <10.0.14393.4886 | |
Microsoft Windows 10 1809 | <10.0.17763.2452 | |
Microsoft Windows 10 1909 | <10.0.18363.2037 | |
Microsoft Windows 10 20h2 | <10.0.19042.1466 | |
Microsoft Windows 10 21h1 | <10.0.19043.1466 | |
Microsoft Windows 10 21h2 | <10.0.19044.1466 | |
Microsoft Windows 11 21h2 | <10.0.22000.434 | |
Microsoft Windows Server | =2022 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =20h2 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows 10 1507 | <10.0.10240.19177 | |
Microsoft Windows 10 1507 | <10.0.10240.19177 | |
Microsoft Windows 10 | =21H1 | |
Microsoft Visual Studio 2019 (includes 16.0 - 16.8) | =16.9 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server | =20H2 | |
Microsoft Visual Studio 2015 | =3 | |
Microsoft Windows 10 | =1909 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | ||
Microsoft Visual Studio 2019 (includes 16.0 – 16.6) | =16.7 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows 10 | =21H1 | |
Microsoft Windows 10 | =21H1 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Visual Studio 2017 (includes 15.0 - 15.8) | =15.9 | |
Microsoft Windows 11 | =21H2 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 10 | =20H2 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | =20H2 | |
Microsoft Windows 11 | =21H2 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 10 | =1909 | |
Microsoft Windows 10 | =1909 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows 10 | =1607 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-21871.
The severity of CVE-2022-21871 is high with a CVSS score of 7.8.
Microsoft Visual Studio 2017 (version 15.0 to 15.9.44), Microsoft Visual Studio 2019 (version 16.0 to 16.7.25), Microsoft Windows 10 (version 1507), Microsoft Windows Server 2016 (version 1607), Microsoft Windows 10 1909, Microsoft Windows 10 20h2, Microsoft Windows 10 21h1, Microsoft Windows Server 2019, Microsoft Windows 11 21h2, and Microsoft Windows Server 2022 are affected by CVE-2022-21871.
The vulnerability allows an attacker to elevate privileges on the affected systems.
Yes, Microsoft has released security updates to address the vulnerability. It is recommended to install the latest updates from Microsoft.