Vulnerability record · CVE-2022-41033 · published 11 October 2022
CVE-2022-41033: Windows COM+ Event System Service type confusion privilege escalation
Microsoft · Windows 10 1507
CVE-2022-41033 is a type confusion (CWE-843) flaw in the Windows COM+ Event System Service that allows a local user to elevate privileges. It affects a broad set of Windows client and server releases, and Microsoft addressed it with an October 2022 update. Because it grants SYSTEM-level access from an unprivileged local session, it is a valuable post-compromise escalation step.
Description
Windows COM+ Event System Service Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is confirmed exploited in the wild per CISA KEV and gives full SYSTEM-level escalation, though it requires local access and a low-privileged account first.
What it is
CVE-2022-41033 is a type confusion (CWE-843) flaw in the Windows COM+ Event System Service that allows a local user to elevate privileges. It affects a broad set of Windows client and server releases, and Microsoft addressed it with an October 2022 update. Because it grants SYSTEM-level access from an unprivileged local session, it is a valuable post-compromise escalation step.
Impact
An attacker with a low-privileged local account gains elevated privileges, with high impact to confidentiality, integrity and availability per the CVSS vector. In practice this yields SYSTEM-level control of the host, enabling credential theft, persistence and defense evasion.
Attack surface
Reached locally (AV:L) by an authenticated low-privileged user (PR:L) with no user interaction (UI:N); no network or remote vector is described. Exploitation requires code execution on the target host, typically after initial access.
Exploitation
It is listed in CISA's Known Exploited Vulnerabilities catalog with a 2022-11-01 remediation due date, indicating exploitation in the wild. EPSS is modest (about 1.7% 30-day probability, ~76th percentile), and no ransomware campaign use is recorded.
What to do
- Apply the Microsoft October 2022 security updates for all affected Windows client and server versions; this is the primary fix.
- Prioritize patching of internet-facing and high-value servers and any host where untrusted users can run code.
- Enforce least privilege and restrict local logon and code execution rights to reduce the pool of accounts that can trigger the flaw.
- Monitor for and remove unpatched or end-of-life builds (for example Windows 7, 8.1, Server 2008/2012) that cannot receive the fix.
- Track KEV remediation deadlines and verify patch compliance across the affected product list.
Detection
- Alert on unexpected child processes of the COM+ Event System service (EventSystem) or svchost instances hosting it, especially those spawning cmd, powershell or other shells.
- Monitor for privilege escalation artifacts: processes gaining SYSTEM tokens, unusual service creation or modification, and suspicious named-pipe or COM object access.
- Correlate local logon events with subsequent high-integrity process creation on the same host to spot escalation chains.
- Hunt for known public proof-of-concept behavior tied to COM+ Event System abuse and review EDR telemetry for anomalous COM object instantiation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-41033 to the Known Exploited Vulnerabilities catalog on 11 October 2022 as "Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 1 November 2022.
Affected products
16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41033 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41033 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-41033 | US Government Resource |
Track CVE-2022-41033 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-41033), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.