CVE-2022-21919
published 2022-01-11CVE-2022-21919: Windows User Profile Service Elevation of Privilege Vulnerability
high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-16
Exploited in the wild
Windows User Profile Service Elevation of Privilege Vulnerability
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19177 | 10.0.10240.19177 |
| microsoft | windows_10_1607 | < 10.0.14393.4886 | 10.0.14393.4886 |
| microsoft | windows_10_1809 | < 10.0.17763.2452 | 10.0.17763.2452 |
| microsoft | windows_10_1909 | < 10.0.18363.2037 | 10.0.18363.2037 |
| microsoft | windows_10_20h2 | < 10.0.19042.1466 | 10.0.19042.1466 |
| microsoft | windows_10_21h1 | < 10.0.19043.1466 | 10.0.19043.1466 |
| microsoft | windows_10_21h2 | < 10.0.19044.1466 | 10.0.19044.1466 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19177 | 10.0.10240.19177 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.4886 | 10.0.14393.4886 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2452 | 10.0.17763.2452 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2452 | 10.0.17763.2452 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2037 | 10.0.18363.2037 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1466 | 10.0.19042.1466 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1466 | 10.0.19043.1466 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19043.1466 | 10.0.19043.1466 |
| microsoft | windows_11_21h2 | < 10.0.22000.434 | 10.0.22000.434 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.434 | 10.0.22000.434 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25829 | 6.1.7601.25829 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25829 | 6.1.7601.25829 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20246 | 6.3.9600.20246 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.25829 | 6.1.7601.25829 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21349 | 6.0.6003.21349 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23584 | 6.2.9200.23584 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.0HIGH
cisa7.0HIGH