LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-26904: Microsoft Windows User Profile Service Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 16, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-26904 to its Known Exploited Vulnerabilities catalog on Apr 25, 2022, with a federal patch deadline of May 16, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

CVE-2022-26904 is a privilege-escalation vulnerability in the Microsoft Windows User Profile Service. An attacker who already has a foothold on a system could abuse it to gain higher privileges. Because the User Profile Service is present on typical Windows endpoints and servers, successful exploitation can turn a limited compromise into full administrative control, which is why defenders need to treat it as a priority.

Public detail on the exact mechanics is limited; CISA describes an unspecified flaw that allows privilege escalation. Confirm all version, patch, and configuration specifics against the Microsoft vendor advisory before acting.

How it works

The weakness is classified as CWE-362, a race-condition issue (concurrent execution using a shared resource with improper synchronization). In this class of flaw, two or more operations race to access or modify the same resource; if the timing is wrong, an attacker can interleave their own actions and obtain a result the software never intended—here, elevated privileges via the User Profile Service.

An attacker who can already run code in a lower-privileged context would attempt to win the race against legitimate User Profile Service operations. Exact exploit steps are not publicly detailed in the provided facts, so treat any proof-of-concept claims with caution and rely on the vendor advisory for technical depth. The outcome of a successful race is privilege escalation on the local Windows host.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the User Profile Service, which is a standard component on client and server editions. Inventory every Windows endpoint and server in your environment—workstations, jump hosts, remote-desktop servers, and domain-joined or standalone machines.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; that remains the primary fix.

If you can't patch immediately

Until the vendor update can be applied, reduce risk with compensating controls.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities frequently serve as a stepping stone to broader compromise and data theft. While known ransomware use is not documented for this CVE, any successful elevation can lead to credential dumping, lateral movement, and exfiltration. If you suspect exploitation, isolate affected hosts, preserve forensic evidence, rotate credentials that may have been exposed, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data to check whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-362
Added to CISA KEVApr 25, 2022
Federal patch deadlineMay 16, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities