CVE-2022-24549: Windows AppX Package Manager Elevation of Privilege Vulnerability
Published Apr 12, 2022
·Updated
Windows AppX Package Manager Elevation of Privilege Vulnerability
Affected Software
41 affected componentsFixes available
Microsoft Windows Server=20H2
Microsoft Windows Server 2019
Microsoft Windows Server 2019
Microsoft Windows 11=21H2
Microsoft Windows 11=21H2
Microsoft Windows Server 2022
Microsoft Windows Server 2022
Microsoft Windows Server 2016
Microsoft Windows Server 2016
Microsoft Windows 10=20H2
Microsoft Windows 10=20H2
Microsoft Windows 10=20H2
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=1607
Microsoft Windows 10=1607
Microsoft Windows 10=21H1
Microsoft Windows 10=21H1
Microsoft Windows 10=21H1
Microsoft Windows 10=21H2
Microsoft Windows 10=21H2
Microsoft Windows 10=21H2
Microsoft Windows 10=1909
Microsoft Windows 10=1909
Microsoft Windows 10=1909
Microsoft Windows 10
Microsoft Windows 10
Microsoft Windows 10
Microsoft Windows 10=20h2
Microsoft Windows 10=21h1
Microsoft Windows 10=21h2
Microsoft Windows 10=1607
Microsoft Windows 10=1809
Microsoft Windows 10=1909
Microsoft Windows 11
Microsoft Windows 11
Microsoft Windows Server 2016
Microsoft Windows Server 2016=20h2
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Event History
Apr 12, 2022
CVE Published
08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Apr 15, 2022
CVE Published
via MITRE·07:04 PM
Data Sourced
via MITRE·07:04 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2022-24549?
CVE-2022-24549 is rated as important by Microsoft due to its potential for elevation of privilege.
2
How do I fix CVE-2022-24549?
To fix CVE-2022-24549, install the security updates provided by Microsoft, specifically the applicable KB updates for your Windows version.
3
Which versions of Windows are affected by CVE-2022-24549?
CVE-2022-24549 affects multiple versions of Windows 10, Windows 11, and Windows Server, including various build numbers.
4
Can CVE-2022-24549 be exploited remotely?
No, CVE-2022-24549 cannot be exploited remotely as it requires local access to execute the attack.
5
What is the impact of CVE-2022-24549 if exploited?
If successfully exploited, CVE-2022-24549 allows an attacker to elevate their privileges on the affected system.