HIGH

CVE-2022-21919

Microsoft Windows 10 1507 2022-01-11 CVSS v3.1
CVSS
7
KEV

Description

Windows User Profile Service Elevation of Privilege Vulnerability

Summary dbcve.org

This is a local privilege escalation vulnerability in the Windows User Profile Service that allows an authenticated attacker to elevate their privileges, likely gaining SYSTEM-level access. The vulnerability stems from improper handling of user profile operations.

Mitigation

Apply the Microsoft security update KB5010342 (February 2022) or subsequent relevant patches to address this vulnerability in affected Windows versions.

Patch Commit

Weakness (CWE)

CWE-59 Link Following (Symlink)

EPSS Score

2.43%
Probability of exploitation in next 30 days
83.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE