ZeroHour

CVE-2022-21919

KEVmass

Local Privilege Escalation in Microsoft Windows User Profile Service

CISA: Microsoft Windows User Profile Service Privilege Escalation Vulnerability

CVSS 3.1
7.0 high
EPSS
3%p87
Published
()
KEV added
AI analysis

The Windows User Profile Service contains a link-following flaw (CWE-59) that lets an authenticated local attacker with low privileges elevate to SYSTEM/administrator rights, typically by planting a junction or symlink that the service follows while handling user profile operations. The attack is local-only (AV:L) with high attack complexity and no user interaction required, so it cannot be exploited remotely or by unauthenticated users. Any environment running the affected Windows releases — Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 per the CPE data — is exposed wherever standard users can execute code. Microsoft shipped the fix in its January 2022 Patch Tuesday release, and CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2022-04-25, confirming exploitation in the wild. Ransomware association is not documented, and no public proof-of-concept is known; EPSS currently puts 30-day exploitation probability at 3.0% (86th percentile).

What to do: Apply Microsoft's January 2022 Patch Tuesday security updates (or any later cumulative/LC updates) to all affected Windows 7/8.1/10/11 clients, Windows RT 8.1 devices, and Windows Server 2008 systems, per CISA's required action. Windows 7/8.1/Server 2008 may require Extended Security Updates where mainstream support has ended. Prioritize hosts that expose interactive logon to untrusted or low-privilege users and verify patch compliance, given the KEV listing confirms active exploitation.

Affected
Microsoft Windows 101507, 1607, 1809, 1909, 20H2, 21H1, 21H2
Microsoft Windows 1121H2
Microsoft Windows 7all editions in scope (no specific build range provided in source data)
Microsoft Windows 8.1all editions in scope (no specific build range provided in source data)
Microsoft Windows RT 8.1all devices in scope (no specific build range provided in source data)
Microsoft Windows Server 2008all editions in scope (no specific build range provided in source data)
Estimated exposure
masshundreds of millions of Windows endpoints and servers (Windows 10/11 installed base is on the order of one billion devices; unpatched share unknown) — Public market-share data puts the combined Windows 10/11 desktop installed base around one billion devices and Windows Server deployments in the millions, so even the unpatched fraction of these versions far exceeds the 1M-device mass…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows User Profile Service Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows 7, windows 8.1, windows rt 8.1, windows server 2008
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news