Junglewise Threat Intelligence

CVE-2022-26904: Microsoft Windows User Profile Service Privilege Escalation Vulnerability

CVE-2022-26904 · Severity: critical · CVSS 7 · Exploited in the wild · Published 2022-04-25

Technologies: Microsoft Windows Server 2022, Microsoft Windows, Microsoft Windows 11, Microsoft Windows 10, Microsoft Windows 8.1, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

The Microsoft Windows User Profile Service contains a race condition vulnerability (CWE-362) that allows for local privilege escalation. An attacker with low privileges could exploit this flaw to gain elevated system permissions.

Affected products

  • Microsoft Windows 10 up to (excluding) 10.0.19044.1645
  • Microsoft Windows 11 up to (excluding) 10.0.22000.613
  • Microsoft Windows Server 2022 up to (excluding) 10.0.20348.643
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1 all

Timeline

  • 2022-04-25: disclosed
  • 2022-04-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-26: other: Initial NIST analysis completed

Related threats