CVE-2022-26904
KEVmassRace-condition privilege escalation in Microsoft Windows User Profile Service
CISA: Microsoft Windows User Profile Service Privilege Escalation Vulnerability
CVE-2022-26904 is a race condition (CWE-362) in the Microsoft Windows User Profile Service (ProfSvc) that allows a local, low-privileged user with valid logon credentials to trigger the flaw and gain elevated privileges on the host. The attack vector is local (AV:L) with high attack complexity, meaning the attacker must win a timing race during the service's handling of user profile operations, and a successful exploit yields high-impact code execution on the target machine, effectively full compromise of that system. Any environment running the affected Windows releases is exposed, spanning Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 per the CPE data. The flaw was patched in Microsoft's April 2022 Patch Tuesday (which fixed over 100 CVEs) and was one of two Windows zero-days known to be actively exploited at the time of the update release; CISA added it to the Known Exploited Vulnerabilities catalog on 2022-04-25. No public proof-of-concept is known, and EPSS puts its probability of exploitation within 30 days at 9.6% (95th percentile), but the KEV listing is direct evidence of in-the-wild exploitation.
What to do: Apply the April 2022 Patch Tuesday security updates (or later cumulative updates) for each affected Windows release per Microsoft's vendor instructions, as required by the CISA KEV listing. Prioritize hosts where untrusted or unprivileged users can log on locally, such as shared workstations, RDP/VDI servers, and multi-user Windows Server 2008 systems, and verify endpoint patch compliance explicitly covers the User Profile Service fix. Until patched, restrict local logon rights to trusted users as an interim mitigation, and treat any post-compromise telemetry on unpatched endpoints as potentially SYSTEM-level attacker activity.
| microsoft Windows 10 | 1507, 1607, 1809, 1909, 20H2, 21H1, 21H2 |
| microsoft Windows 11 | 21H2 |
| microsoft Windows 7 | all supported releases (no version qualifier in source data) |
| microsoft Windows 8.1 | all supported releases (no version qualifier in source data) |
| microsoft Windows RT 8.1 | all supported releases (no version qualifier in source data) |
| microsoft Windows Server 2008 | all supported releases (no version qualifier in source data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows User Profile Service Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows 7, windows 8.1, windows rt 8.1, windows server 2008
- Weakness
- CWE-362
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H