ZeroHour

CVE-2022-26904

KEVmass

Race-condition privilege escalation in Microsoft Windows User Profile Service

CISA: Microsoft Windows User Profile Service Privilege Escalation Vulnerability

CVSS 3.1
7.0 high
EPSS
10%p95
Published
()
KEV added
AI analysis

CVE-2022-26904 is a race condition (CWE-362) in the Microsoft Windows User Profile Service (ProfSvc) that allows a local, low-privileged user with valid logon credentials to trigger the flaw and gain elevated privileges on the host. The attack vector is local (AV:L) with high attack complexity, meaning the attacker must win a timing race during the service's handling of user profile operations, and a successful exploit yields high-impact code execution on the target machine, effectively full compromise of that system. Any environment running the affected Windows releases is exposed, spanning Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 per the CPE data. The flaw was patched in Microsoft's April 2022 Patch Tuesday (which fixed over 100 CVEs) and was one of two Windows zero-days known to be actively exploited at the time of the update release; CISA added it to the Known Exploited Vulnerabilities catalog on 2022-04-25. No public proof-of-concept is known, and EPSS puts its probability of exploitation within 30 days at 9.6% (95th percentile), but the KEV listing is direct evidence of in-the-wild exploitation.

What to do: Apply the April 2022 Patch Tuesday security updates (or later cumulative updates) for each affected Windows release per Microsoft's vendor instructions, as required by the CISA KEV listing. Prioritize hosts where untrusted or unprivileged users can log on locally, such as shared workstations, RDP/VDI servers, and multi-user Windows Server 2008 systems, and verify endpoint patch compliance explicitly covers the User Profile Service fix. Until patched, restrict local logon rights to trusted users as an interim mitigation, and treat any post-compromise telemetry on unpatched endpoints as potentially SYSTEM-level attacker activity.

Affected
microsoft Windows 101507, 1607, 1809, 1909, 20H2, 21H1, 21H2
microsoft Windows 1121H2
microsoft Windows 7all supported releases (no version qualifier in source data)
microsoft Windows 8.1all supported releases (no version qualifier in source data)
microsoft Windows RT 8.1all supported releases (no version qualifier in source data)
microsoft Windows Server 2008all supported releases (no version qualifier in source data)
Estimated exposure
mass≈1 billion+ Windows devices (Windows 10/11 alone ran on 1.4B+ monthly-active devices at disclosure) — The affected range spans nearly the entire Windows installed base at the time (Windows 7 through Windows 11 21H2 plus Windows Server 2008), and Microsoft has publicly reported over 1.4 billion monthly active Windows 10/11 devices, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows User Profile Service Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows 7, windows 8.1, windows rt 8.1, windows server 2008
Weakness
CWE-362
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news