
CVE-2022-22047 is a Windows local privilege escalation vulnerability in CSRSS that introduced researchers to a new bug class: Activation Context Cache Poisoning. By poisoning CSRSS's activation context cache, an attacker can influence how privileged processes resolve and load DLL dependencies, ultimately leading to SYSTEM privileges. It's an excellent case study in CSRSS, activation contexts, SxS manifests, and Windows DLL loading internals. https://www.zerodayinitiative.com/blog/2023/1/23/activation-context-cache-poisoning-exploiting-csrss-for-privilege-escalation
Post summary
The post discloses CVE‑2022‑22047, a local privilege escalation flaw in Windows CSRSS via activation context cache poisoning that can elevate to SYSTEM privileges, and links to a blog likely detailing the exploit.
