HIGH

CVE-2022-26904

Microsoft Windows 10 1507 2022-04-15 CVSS v3.1
CVSS
7
KEV

Description

Windows User Profile Service Elevation of Privilege Vulnerability

Summary dbcve.org

CVE-2022-26904 is an elevation of privilege vulnerability in the Windows User Profile Service that allows an authenticated attacker to gain higher privileges on the affected system. The vulnerability stems from improper handling of user profile operations, potentially enabling a local attacker to escalate privileges beyond their assigned user context.

Mitigation

Apply the Microsoft security update for CVE-2022-26904, which patches the Windows User Profile Service vulnerability. Prioritize patching domain controllers and systems with privileged user access.

Patch Commit

Weakness (CWE)

CWE-362 Race Condition

EPSS Score

16.95%
Probability of exploitation in next 30 days
97th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE