CVE-2022-23291: Windows DWM Core Library Elevation of Privilege Vulnerability
Published Mar 8, 2022
·Updated
Windows DWM Core Library Elevation of Privilege Vulnerability
Affected Software
32 affected componentsFixes available
Microsoft Windows Server=20H2
Microsoft Windows Server 2019
Microsoft Windows Server 2019
Microsoft Windows 11=21H2
Microsoft Windows 11=21H2
Microsoft Windows Server 2022
Microsoft Windows Server 2022
Microsoft Windows 10=20H2
Microsoft Windows 10=20H2
Microsoft Windows 10=20H2
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=21H1
Microsoft Windows 10=21H1
Microsoft Windows 10=21H1
Microsoft Windows 10=21H2
Microsoft Windows 10=21H2
Microsoft Windows 10=21H2
Microsoft Windows 10=1909
Microsoft Windows 10=1909
Microsoft Windows 10=1909
Microsoft Windows 10=20h2
Microsoft Windows 10=21h1
Microsoft Windows 10=21h2
Microsoft Windows 10=1809
Microsoft Windows 10=1909
Microsoft Windows 11
Microsoft Windows 11
Microsoft Windows Server=20h2
Microsoft Windows Server=2022
Microsoft Windows Server 2019
Event History
Mar 8, 2022
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
Mar 9, 2022
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2022-23291?
CVE-2022-23291 has a severity rating of Important due to its potential for elevation of privilege.
2
How do I fix CVE-2022-23291?
To fix CVE-2022-23291, apply the relevant security updates provided by Microsoft for your affected version of Windows.
3
What versions of Windows are affected by CVE-2022-23291?
CVE-2022-23291 affects multiple versions of Windows 10, Windows 11, and Windows Server, specifically versions 1809, 1909, 20H2, 21H1, and 21H2.
4
What kind of vulnerability is CVE-2022-23291?
CVE-2022-23291 is an elevation of privilege vulnerability in the Windows DWM Core Library.
5
Is there a known exploit for CVE-2022-23291?
As of now, Microsoft has not reported any known active exploit for CVE-2022-23291.