Executive brief
The Microsoft Windows User Profile Service contains a privilege escalation vulnerability caused by improper link resolution before file access (link following). An authenticated attacker with local access could exploit this to gain elevated system privileges.
Affected products
- Microsoft Windows 10 1507, 1607, 1809, 1909, 20H2, 21H1, 21H2
- Microsoft Windows 11 21H2
- Microsoft Windows Server 2008, 2012, 2016, 2019, 2022, 20H2
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1 all
Timeline
- 2022-04-25: disclosed
- 2022-04-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-04-25: patched: Microsoft released security updates to address this vulnerability.
- exploited: Confirmed by CISA to be exploited in the wild.