CVE-2022-41054: Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.3650Patch KB5019966 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5501Patch KB5019964 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.1219Patch KB5019961 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1249Fixed in 10.0.20348.1251Patch KB5019080 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.819Patch KB5019980 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.2251Patch KB5019959
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41054?
CVE-2022-41054 has a severity rating of important, indicating a significant risk of exploitation.
How do I fix CVE-2022-41054?
To address CVE-2022-41054, apply the relevant security updates provided by Microsoft for your affected version of Windows.
Which versions of Windows are affected by CVE-2022-41054?
CVE-2022-41054 affects multiple versions of Windows including Windows 10, Windows 11, and various editions of Windows Server.
Can CVE-2022-41054 lead to system compromise?
Yes, CVE-2022-41054 can potentially allow an attacker to elevate privileges on the affected system.
Is CVE-2022-41054 being actively exploited?
There are no current reports indicating that CVE-2022-41054 is being actively exploited, but it is still a critical vulnerability that should be patched promptly.