{"cveID":"CVE-2022-21971","vendorProject":"Microsoft","product":"Windows","vulnerabilityName":"Microsoft Windows Runtime Remote Code Execution Vulnerability","dateAdded":"2022-08-18","shortDescription":"Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-09-08","knownRansomwareCampaignUse":"Unknown","notes":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21971;  https://nvd.nist.gov/vuln/detail/CVE-2022-21971","cwes":["CWE-824"],"year":2022,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2022-21971","technique":"T1204.001","technique_name_at_mapping":"Malicious Link","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"This vulnerability is exploited when an authenticated user is convinced by an attacker to download and open a specially crafted file from a website, which grants the attacker access to the victim's computer. No articles have been released to the public showing that this vulnerability has been executed in the wild or provides any information on how an exploitation is carried out. ","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21971","https://www.securityweek.com/sap-vulnerability-exploited-attacks-after-details-disclosed-hacker-conferences/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-21971","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"primary_impact","capability_group":"code_execution","comments":"This vulnerability is exploited when an authenticated user is convinced by an attacker to download and open a specially crafted file from a website, which grants the attacker access to the victim's computer. No articles have been released to the public showing that this vulnerability has been executed in the wild or provides any information on how an exploitation is carried out. ","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21971","https://www.securityweek.com/sap-vulnerability-exploited-attacks-after-details-disclosed-hacker-conferences/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1204.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Malicious Link","name_at_mapping":"Malicious Link","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":4,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}