Patch now. It under exploitation confirmed by CISA and has a working public exploit.
ssvc Actcvss 7.8epss 76%
from disclosure to weapon21 days
Published on NVDJan 13
1st PoC+21d
metasploitJan 13
CISA KEV+2689d
exploitation probability
76%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
3 public exploit(s)
Action required by CISAfederal deadline: 2022-06-15
Apply updates per vendor instructions.
In short
A flaw in Windows' TS WebProxy component allows an attacker to bypass security restrictions by using specially crafted file paths, enabling them to gain higher privileges on the system. This is dangerous because it lets low-privilege users escalate their access without proper authorization.
Technical detail
Directory traversal vulnerability in TS WebProxy (TSWbPrxy) enables privilege escalation from Low Integrity to Medium Integrity context via maliciously crafted executable pathnames. The vulnerability exploits insufficient path validation, allowing remote or local attackers to circumvent integrity level restrictions and elevate privileges.
Summary generated and translated by AI from the official description.
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an executable file, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Directory Traversal Elevation of Privilege Vulnerability."