CVE-2022-41125: Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
Other sources
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20671Fixed in 6.3.9600.20670Patch KB5020010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23968Patch KB5020003 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20670Patch KB5020010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5501Patch KB5019964 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19567Patch KB5019970 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.819Patch KB5019980 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.1219Patch KB5019961 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1249Fixed in 10.0.20348.1251Patch KB5019080 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.2251Patch KB5019959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.3650Patch KB5019966
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41125?
CVE-2022-41125 has a critical severity rating as it allows an attacker to gain SYSTEM-level privileges.
How do I fix CVE-2022-41125?
To fix CVE-2022-41125, apply the latest security updates provided by Microsoft for your affected Windows version.
What versions of Windows are affected by CVE-2022-41125?
CVE-2022-41125 affects multiple versions of Windows including Windows 10 and Windows 11 in various editions.
What type of vulnerability is CVE-2022-41125?
CVE-2022-41125 is classified as an Elevation of Privilege vulnerability in the Windows Cryptographic Next Generation (CNG) Key Isolation Service.
Who is the vendor responsible for CVE-2022-41125?
The vendor responsible for CVE-2022-41125 is Microsoft.