Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
ssvc Actcvss 6.6epss 4.1%
from disclosure to weapon2013 days
Published on NVDAug 15
1st PoC+2013d
CISA KEV+2475d
exploitation probability
4.1%top 10% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-06-15
Apply updates per vendor instructions.
In short
Windows Mount Manager doesn't properly handle symbolic links on USB devices, allowing someone with physical access to a computer to connect a malicious USB drive and run unauthorized code with elevated privileges.
Technical detail
A symbolic link handling vulnerability in Windows Mount Manager allows local attackers with physical device access to escalate privileges by connecting a crafted USB device. The flaw fails to properly validate symlink targets during mount operations, enabling arbitrary code execution in a privileged context without requiring user interaction beyond device connection.
Summary generated and translated by AI from the official description.
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Mount Manager Elevation of Privilege Vulnerability."