CVE-2022-21919

HIGH KEV

Windows User Profile Service - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-21919 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added April 25, 2022.

Description

Windows User Profile Service Elevation of Privilege Vulnerability

Scores

CVSS v3 7.0
EPSS 0.0031
EPSS Percentile 54.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-04-25
VulnCheck KEV 2022-04-25
InTheWild.io 2022-04-25
ENISA EUVD EUVD-2022-27075
CWE
CWE-59
Status published
Products (19)
microsoft/windows_10_1507 < 10.0.10240.19177 (2 CPE variants)
microsoft/windows_10_1607 < 10.0.14393.4886 (2 CPE variants)
microsoft/windows_10_1809 < 10.0.17763.2452 (2 CPE variants)
microsoft/windows_10_1909 < 10.0.18363.2037
microsoft/windows_10_20h2 < 10.0.19042.1466
microsoft/windows_10_21h1 < 10.0.19043.1466
microsoft/windows_10_21h2 < 10.0.19044.1466
microsoft/windows_11_21h2 < 10.0.22000.434
microsoft/windows_7
microsoft/windows_8.1
... and 9 more
Published Jan 11, 2022
KEV Added Apr 25, 2022
Tracked Since Feb 18, 2026