Security readout for executives and security teams
Plain-English summary
CVE-2022-30202 is a Windows privilege escalation flaw in ALPC, a local Windows communication mechanism. An attacker would already need low-privileged local access, but successful exploitation could give broad control over confidentiality, integrity, and availability on the affected machine.
Executive priority
Patch in normal high-severity Windows maintenance cycles, with faster handling for shared servers and remote-access endpoints. This is not described as remotely exploitable or actively exploited in the provided sources, but it can amplify an existing foothold.
Technical view
The CVSS 3.1 vector is 7.0 high: local attack vector, high complexity, low privileges required, no user interaction, unchanged scope, and high impact to confidentiality, integrity, and availability. The affected list includes multiple Windows client and server versions, including Windows 7, 8.1, 10, 11, and Server 2008 through 2022 variants.
Likely exposure
Exposure is limited to affected Windows systems where an attacker can obtain local low-privileged access. Endpoint fleets, RDS hosts, shared servers, and older Windows deployments deserve attention. The source bundle does not identify network-only exploitation.
Exploitation context
The bundle does not show CISA KEV listing or cited evidence of active exploitation. Exploit maturity is marked unproven in the CVSS vector. Treat this mainly as a post-access privilege escalation risk until vendor or threat intelligence says otherwise.
Researcher notes
Key gaps are root-cause detail, affected build thresholds, and exact update mapping beyond the MSRC advisory. Avoid assuming exploit availability. Validation should focus on OS version, patch state, and whether local low-privilege access paths exist.
Mitigation direction
- Apply Microsoft security updates according to the MSRC advisory for each affected Windows version.
- Prioritize systems with multiple local users, remote access, or exposed application workloads.
- Retire or isolate unsupported legacy Windows assets where patching is unavailable.
- Use least privilege to reduce value of low-privileged local compromise.
Validation and detection
- Inventory Windows versions and compare them against the affected product list.
- Confirm applicable Microsoft security updates are installed for each affected build.
- Review vulnerability scanner findings for CVE-2022-30202 across endpoints and servers.
- Check whether high-risk shared or remote-access hosts remain unpatched.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Privilege behavior lookup
The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2022-30202 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C15.9Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7HighVector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Source materials
- CVE List V5 sourceCVE List V5
- Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege VulnerabilityCVE reference · vendor-advisory
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
