CVE-2022-23288: Windows DWM Core Library Elevation of Privilege Vulnerability
Published Mar 8, 2022
·Updated
Windows DWM Core Library Elevation of Privilege Vulnerability
Affected Software
28 affected componentsFixes available
Microsoft Windows Server=20H2
Microsoft Windows Server 2019
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Microsoft Windows Server 2022
Microsoft Windows 10=20H2
Microsoft Windows 10=20H2
Microsoft Windows 10=20H2
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=21H1
Microsoft Windows 10=21H1
Microsoft Windows 10=21H1
Microsoft Windows 10=21H2
Microsoft Windows 10=21H2
Microsoft Windows 10=21H2
Microsoft Windows 10=1909
Microsoft Windows 10=1909
Microsoft Windows 10=1909
Microsoft Windows 10=20h2
Microsoft Windows 10=21h1
Microsoft Windows 10=21h2
Microsoft Windows 10=1809
Microsoft Windows 10=1909
Microsoft Windows Server=20h2
Microsoft Windows Server=2022
Microsoft Windows Server 2019
Event History
Mar 8, 2022
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
Mar 9, 2022
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-23288?
CVE-2022-23288 is a vulnerability in the Windows DWM Core Library that allows for elevation of privilege.
2
Which versions of Windows are affected by CVE-2022-23288?
Windows 10 versions 21H2, 20H2, 21H1, 1909, and Windows Server 2019 are affected by CVE-2022-23288.
3
What is the severity of CVE-2022-23288?
CVE-2022-23288 has a severity level of high (7 out of 10).
4
How can I fix CVE-2022-23288?
To fix CVE-2022-23288, apply the relevant patches provided by Microsoft. Links to the patches can be found in the references.
5
Where can I find more information about CVE-2022-23288?
You can find more information about CVE-2022-23288 on the Microsoft Security Response Center website. The reference link provides additional details.