LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-21919: Microsoft Windows User Profile Service Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 16, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-21919 to its Known Exploited Vulnerabilities catalog on Apr 25, 2022, with a federal patch deadline of May 16, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

Overview

CVE-2022-21919 is a privilege escalation vulnerability in the Microsoft Windows User Profile Service. An attacker who already has a foothold on a system could abuse it to gain higher privileges. Privilege escalation flaws matter because they turn limited access into full control of the host, enabling further lateral movement, persistence, or data access. Public detail on the exact root cause is limited; treat the CISA description and the vendor advisory as the authoritative sources.

CISA characterizes the issue as an unspecified vulnerability in the User Profile Service that allows privilege escalation. Known ransomware use is not documented. The required action is to apply updates per vendor instructions.

How it works

The weakness is tracked as CWE-1386 and affects the Windows User Profile Service, the component that loads and manages user profiles during logon and session activity. Privilege-escalation bugs in this class typically arise when the service mishandles profile paths, junctions, or related objects in a way that lets a lower-privileged process influence higher-privileged operations.

An attacker who can already run code as a standard user would attempt to trigger the vulnerable behavior so that the service performs an action with elevated rights on the attacker’s behalf. Exact exploit mechanics are not provided in the public summary; do not assume specific techniques. Confirm any technical details against the Microsoft advisory for this CVE.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the User Profile Service—essentially the majority of client and server installations that support interactive or remote user sessions. Inventory every Windows endpoint and server in your environment.

If you cannot map a host to a patched build, treat it as potentially affected until confirmed otherwise.

How to remediate

Patch first. Apply the Microsoft security update that remediates CVE-2022-21919 according to the vendor’s instructions and your normal change process. Prioritize domain-joined workstations, jump hosts, and servers that allow interactive or RDP logons, because those systems are the most common targets for local privilege escalation.

If you can't patch immediately

When immediate patching is not possible, reduce the attack surface and increase detection until the update can be applied.

These steps are compensating controls only. They do not replace the vendor update.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities frequently appear in breach chains once an attacker has initial access. If you have evidence of exploitation or unpatched systems that were reachable by untrusted users, follow your incident-response process: isolate affected hosts, preserve volatile evidence, and hunt for persistence and lateral movement. Known ransomware use of this specific CVE is not documented, but that does not rule out other post-exploitation activity.

As a quick external check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps. That scan does not replace internal forensics; it only helps gauge whether related accounts may need password resets or further monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-1386
Added to CISA KEVApr 25, 2022
Federal patch deadlineMay 16, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities