Untrusted Pointer Dereference (CWE-822)
CWE-822 describes a product that takes a value from an untrusted source, converts it to a pointer and dereferences it. Forms include an untrusted value invoked as a function call and pointers crossing from user space into OS kernels or drivers. MITRE places it under CWE-119.
About CWE-822
A read through the pointer can disclose sensitive memory, and an invalid address can crash the product. A write or function call through it may modify memory or execute code.
Mitigations
- +Use a language that does not allow out-of-bounds memory operations, noting that native code interfaces may still be exposed (from parent CWE-119).
- +Enable compiler buffer overflow detection mechanisms as defense in depth (from parent CWE-119).
- +Use ASLR and position-independent executables to make memory addresses less predictable (from parent CWE-119).
Detection
Automated static analysis (SAST) is rated highly effective, and runtime checkers such as AddressSanitizer have moderate effectiveness when combined with crafted inputs.
CWE-822 Vulnerabilities
5 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-24990 | Windows Agere Modem Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 6.4% | KEV | 2025-10-14 |
| CVE-2024-35250 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 25.2% | KEV | 2024-06-11 |
| CVE-2024-21338 | Windows Kernel Elevation of Privilege Vulnerability | Microsoft | 7.8 | 59.8% | KEV | 2024-02-13 |
| CVE-2023-29360 | Microsoft Streaming Service Elevation of Privilege Vulnerability | Microsoft | 8.4 | 21.6% | KEV | 2023-06-13 |
| CVE-2023-36033 | Windows DWM Core Library Elevation of Privilege Vulnerability | Microsoft | 7.8 | 10.9% | KEV | 2023-11-14 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-822?→
CWE-822 is untrusted pointer dereference: a value supplied from outside is used as a memory address and then accessed.
Where does CWE-822 typically appear?→
MITRE mentions OS kernels and drivers, where a pointer may enter from user space through an API or system call.
How many exploited vulnerabilities are classified as CWE-822?→
This database lists 5 CVE records mapped to CWE-822 by their CVE Numbering Authority. 5 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 1 to known ransomware campaigns. Examples include CVE-2025-24990, CVE-2024-35250, CVE-2024-21338.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.