CVE-2022-21919
published 2022-01-11CVE-2022-21919: Windows User Profile Service Elevation of Privilege Vulnerability
PriorityP181high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-16
Exploited in the wild
EPSS
2.95%
85.7th percentile
Windows User Profile Service Elevation of Privilege Vulnerability
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19177 | 10.0.10240.19177 |
| microsoft | windows_10_1607 | < 10.0.14393.4886 | 10.0.14393.4886 |
| microsoft | windows_10_1809 | < 10.0.17763.2452 | 10.0.17763.2452 |
| microsoft | windows_10_1909 | < 10.0.18363.2037 | 10.0.18363.2037 |
| microsoft | windows_10_20h2 | < 10.0.19042.1466 | 10.0.19042.1466 |
| microsoft | windows_10_21h1 | < 10.0.19043.1466 | 10.0.19043.1466 |
| microsoft | windows_10_21h2 | < 10.0.19044.1466 | 10.0.19044.1466 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19177 | 10.0.10240.19177 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.4886 | 10.0.14393.4886 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2452 | 10.0.17763.2452 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2452 | 10.0.17763.2452 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2037 | 10.0.18363.2037 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1466 | 10.0.19042.1466 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1466 | 10.0.19043.1466 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19043.1466 | 10.0.19043.1466 |
| microsoft | windows_11_21h2 | < 10.0.22000.434 | 10.0.22000.434 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.434 | 10.0.22000.434 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25829 | 6.1.7601.25829 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25829 | 6.1.7601.25829 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20246 | 6.3.9600.20246 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.25829 | 6.1.7601.25829 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21349 | 6.0.6003.21349 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23584 | 6.2.9200.23584 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for malicious DLL being planted in a system directory followed by a UAC prompt, which triggers ProfSrv (User Profile Service) to load and execute the DLL as NT AUTHORITY\SYSTEM. ↗
- →Alert on suspicious junction creation activity by the User Profile Service (ProfSrv), particularly involving unexpected directory structure manipulation via CreateDirectoryJunction(). ↗
- →Detect processes spawned as NT AUTHORITY\SYSTEM that originate from ProfSrv or are associated with a UAC elevation event triggered by a non-admin user login. ↗
- ·Exploit requires the attacking user to have UAC set to the highest level ('Always Notify Me When'); if UAC has been lowered from default, the exploit path to SYSTEM execution via this technique will not work. ↗
- ·The second user account used in the exploit must be a non-admin user who has previously logged in at least once; admin accounts or never-logged-in accounts will not satisfy the exploit preconditions. ↗
- ·CVE-2022-21919 is itself a patch bypass of CVE-2021-34484; the Metasploit module targets the further bypass CVE-2022-26904, meaning detections should account for the full patch bypass chain. ↗
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.0HIGH
cisa7.0HIGH
vendor_msrc7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m4qv-hj8q-qx52: Windows User Profile Service Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-01-12·CVSS 7.0
CVE-2022-21895 [HIGH] CWE-269 GHSA-m4qv-hj8q-qx52: Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21919.
GHSA
GHSA-wmfg-rc3x-58v3: Windows User Profile Service Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-01-12·CVSS 7.8
CVE-2022-21919 [HIGH] CWE-269 GHSA-wmfg-rc3x-58v3: Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21895.
VulnCheck
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
vulncheck·2022·CVSS 7.0
CVE-2022-21919 [HIGH] CWE-1386 Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://mandiant.widen.net/s/dlzgn6w26n/m-trends-2023; https://www.cisa.gov/sites/default/files/2023-08/CSRB_Lapsus%24_508c.pdf
Remediation Due: 2022-05-16
CISA
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
cisa·2022-04-25·CVSS 7.0
CVE-2022-21919 [HIGH] CWE-1386 Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-21919
Remediation Due Date: 2022-05-16
Microsoft
Windows User Profile Service Elevation of Privilege Vulnerability
vendor_msrc·2022-01-11·CVSS 7.0
CVE-2022-21919 [HIGH] Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service: Windows User Profile Service
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009557
Reference: https://support.microsoft.com/help/5009557
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009545
Reference: https://support.microsoft.com/help/5009545
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009543
Reference: https://support.microsoft.com/help/5009543
Reference: https://catalog.upd
No detection rules found.
Securelist
IT threat evolution in Q1 2022. Non-mobile statistics
blogs_securelist·2022-05-27
IT threat evolution in Q1 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Geography of financial malware attacks
TOP 10 banking malware families
Ransomware programs
Quarterly trends and highlights
Law enforcement successes
HermeticWiper, HermeticRansom and RUransom, etc.
Conti source-code leak
Attacks on NAS devices
Maze Decryptor
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarter highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat
Securelist
PC malware statistics, Q1 2022
blogs_securelist·2022-05-27
PC malware statistics, Q1 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q1 2022
- IT threat evolution in Q1 2022. Non-mobile statistics
- IT threat evolution in Q1 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q1 2022:
- Kaspersky solutions blocked 1,216,350,437 attacks from online resources across the globe.
- Web Anti-Virus recognized 313,164,030 unique URLs as malicious.
- Attempts to run malware
Tenable
Microsoft’s January 2022 Patch Tuesday Addresses 97 CVEs (CVE-2022-21907)
blogs_tenable·2022-01-11·CVSS 9.8
[CRITICAL] Microsoft’s January 2022 Patch Tuesday Addresses 97 CVEs (CVE-2022-21907)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
2022-01-11
Published
2022-04-25
Added to CISA KEV
Exploited in the wild