CVE-2022-21919
KEVmassLocal Privilege Escalation in Microsoft Windows User Profile Service
CISA: Microsoft Windows User Profile Service Privilege Escalation Vulnerability
The Windows User Profile Service contains a link-following flaw (CWE-59) that lets an authenticated local attacker with low privileges elevate to SYSTEM/administrator rights, typically by planting a junction or symlink that the service follows while handling user profile operations. The attack is local-only (AV:L) with high attack complexity and no user interaction required, so it cannot be exploited remotely or by unauthenticated users. Any environment running the affected Windows releases — Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 per the CPE data — is exposed wherever standard users can execute code. Microsoft shipped the fix in its January 2022 Patch Tuesday release, and CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2022-04-25, confirming exploitation in the wild. Ransomware association is not documented, and no public proof-of-concept is known; EPSS currently puts 30-day exploitation probability at 3.0% (86th percentile).
What to do: Apply Microsoft's January 2022 Patch Tuesday security updates (or any later cumulative/LC updates) to all affected Windows 7/8.1/10/11 clients, Windows RT 8.1 devices, and Windows Server 2008 systems, per CISA's required action. Windows 7/8.1/Server 2008 may require Extended Security Updates where mainstream support has ended. Prioritize hosts that expose interactive logon to untrusted or low-privilege users and verify patch compliance, given the KEV listing confirms active exploitation.
| Microsoft Windows 10 | 1507, 1607, 1809, 1909, 20H2, 21H1, 21H2 |
| Microsoft Windows 11 | 21H2 |
| Microsoft Windows 7 | all editions in scope (no specific build range provided in source data) |
| Microsoft Windows 8.1 | all editions in scope (no specific build range provided in source data) |
| Microsoft Windows RT 8.1 | all devices in scope (no specific build range provided in source data) |
| Microsoft Windows Server 2008 | all editions in scope (no specific build range provided in source data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows User Profile Service Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows 7, windows 8.1, windows rt 8.1, windows server 2008
- Weakness
- CWE-59
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H