Junglewise Threat Intelligence

CVE-2022-21919: Microsoft Windows User Profile Service Privilege Escalation Vulnerability

CVE-2022-21919 · Severity: critical · CVSS 7 · Exploited in the wild · Published 2022-04-25

Technologies: Microsoft Windows, Microsoft Windows 11, Microsoft Windows 8.1, Microsoft Windows 7, Microsoft Windows 10, Microsoft Windows Server. Vendors: Microsoft.

Executive brief

The Microsoft Windows User Profile Service contains a privilege escalation vulnerability caused by improper link resolution before file access (link following). An authenticated attacker with local access could exploit this to gain elevated system privileges.

Affected products

  • Microsoft Windows 10 1507, 1607, 1809, 1909, 20H2, 21H1, 21H2
  • Microsoft Windows 11 21H2
  • Microsoft Windows Server 2008, 2012, 2016, 2019, 2022, 20H2
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1 all

Timeline

  • 2022-04-25: disclosed
  • 2022-04-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-25: patched: Microsoft released security updates to address this vulnerability.
  • exploited: Confirmed by CISA to be exploited in the wild.

Related threats