← back
CVE-2022-21919

Windows User Profile Service Elevation of Privilege Vulnerability

CVSS 7 HIGHEPSS 2.9%● KEVCWE-59
Vexday Risk Score
51Attention
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7EPSS 2.9%KEV simPoC Nuclei Metasploit Patch referenciado
Lifecycle
11 Jan 2022Published on NVD
25 Apr 2022Active exploitation (CISA KEV)
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

A flaw in Windows User Profile Service allows an attacker to gain higher privileges than they should have on a system. This matters because it could let someone take control of sensitive system functions and access other users' data.

Technical detail

CWE-59 (Improper Link Resolution Before File Access) in the Windows User Profile Service allows local attackers to escalate privileges through symlink or junction point manipulation during profile directory operations. Exploitation requires local access but no special privileges, and successful exploitation grants SYSTEM-level code execution.

Summary generated and translated by AI from the official description.
Windows User Profile Service Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →