CVE-2022-26904
published 2022-04-15CVE-2022-26904: Windows User Profile Service Elevation of Privilege Vulnerability
PriorityP180high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-16
Exploited in the wild
EPSS
9.82%
95.0th percentile
Windows User Profile Service Elevation of Privilege Vulnerability
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19265 | 10.0.10240.19265 |
| microsoft | windows_10_1607 | < 10.0.14393.5066 | 10.0.14393.5066 |
| microsoft | windows_10_1809 | < 10.0.17763.2803 | 10.0.17763.2803 |
| microsoft | windows_10_1909 | < 10.0.18363.2212 | 10.0.18363.2212 |
| microsoft | windows_10_20h2 | < 10.0.19042.1645 | 10.0.19042.1645 |
| microsoft | windows_10_21h1 | < 10.0.19043.1645 | 10.0.19043.1645 |
| microsoft | windows_10_21h2 | < 10.0.19044.1645 | 10.0.19044.1645 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19265 | 10.0.10240.19265 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5066 | 10.0.14393.5066 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2803 | 10.0.17763.2803 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2803 | 10.0.17763.2803 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2212 | 10.0.18363.2212 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1645 | 10.0.19042.1645 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1645 | 10.0.19043.1645 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1645 | 10.0.19044.1645 |
| microsoft | windows_11_21h2 | < 10.0.22000.613 | 10.0.22000.613 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.613 | 10.0.22000.613 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25924 | 6.1.7601.25924 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25924 | 6.1.7601.25924 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20337 | 6.3.9600.20337 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.25924 | 6.1.7601.25924 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21446 | 6.0.6003.21446 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23679 | 6.2.9200.23679 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for malicious DLL plants in system directories followed by a UAC prompt, which triggers ProfSrv (User Profile Service) to load and execute the DLL as NT AUTHORITY\SYSTEM. ↗
- →Detect race condition exploitation attempts against the Windows User Profile Service (ProfSrv); successful exploitation requires winning a race condition. ↗
- →Alert on unexpected junction creation within user profile directories, particularly where directory structures are manipulated to point to system paths, as this is the core primitive of the exploit. ↗
- →This is a patch bypass chain: monitor for exploitation patterns previously associated with CVE-2021-34484 and CVE-2022-21919, as both prior patches were bypassed and the same technique applies. ↗
- ·Exploitation requires the attacking user to have UAC set to the highest level ('Always Notify Me When'); if UAC has been lowered from the default, the exploit path to NT AUTHORITY\SYSTEM via this technique will not work. ↗
- ·The second user account used in the exploit must be a non-admin user who has logged in at least once before; admin accounts or never-logged-in accounts will not satisfy the exploit's requirements. ↗
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa7.0HIGH
vendor_msrc7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
cisa·2022-04-25·CVSS 7.0
CVE-2022-26904 [HIGH] CWE-362 Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-26904
Remediation Due Date: 2022-05-16
Microsoft
Windows User Profile Service Elevation of Privilege Vulnerability
vendor_msrc·2022-04-12·CVSS 7.0
CVE-2022-26904 [HIGH] Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
Windows User Profile Service: Windows User Profile Service
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5012647
Reference: https://support.microsoft.com/help/5012647
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5012591
Reference:
GHSA
GHSA-cf7g-gj99-69w3: Windows User Profile Service Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-04-16
CVE-2022-26904 [HIGH] CWE-362 GHSA-cf7g-gj99-69w3: Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability.
VulnCheck
Microsoft Windows CLFS Driver Privilege Escalation Vulnerability
vulncheck·2022·CVSS 7.8
CVE-2022-24521 [HIGH] CWE-787 Microsoft Windows CLFS Driver Privilege Escalation Vulnerability
Microsoft Windows CLFS Driver Privilege Escalation Vulnerability
Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2022-Apr; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.covertswarm.com/post/multiple-windows-zero-days-cve-2022-24521-cve-2022-26904-and-cve-2022-26809; https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius/; https://www.bleepingcomputer.com/news/se
VulnCheck
Remote Procedure Call Runtime Remote Code Execution
vulncheck·2022·CVSS 9.8
CVE-2022-26809 [CRITICAL] Remote Procedure Call Runtime Remote Code Execution
Remote Procedure Call Runtime Remote Code Execution
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Affected: Microsoft Windows
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.covertswarm.com/post/multiple-windows-zero-days-cve-2022-24521-cve-2022-26904-and-cve-2022-26809; https://www.group-ib.com/resources/research-hub/hi-tech-crime-trends-2022/
Exploit PoC: https://vulncheck.com/xdb/bc623cfe5572
VulnCheck
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
vulncheck·2022·CVSS 7.0
CVE-2022-26904 [HIGH] CWE-362 Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.covertswarm.com/post/multiple-windows-zero-days-cve-2022-24521-cve-2022-26904-and-cve-2022-26809; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-05-16
No detection rules found.
Qualys
April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical.
blogs_qualys·2022-04-12·CVSS 8.8
[HIGH] April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
Notable Microsoft Vulnerabilities Patched
Notable Adobe Vulnerabilities Patched
About Qualys Patch Tuesday
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Monthly Webinar Series: This Month in Vulnerabilities & Patches
Join the Webinar This Month in Vulnerabilities & Patches
Contributor
## Microsoft Patch Tuesday Summary
Microsoft has fixed 145 vulnerabilities, including 17 Microsoft Edge vulnerabilities, in the April 2022 update, with ten classified as critical as they allow Remote Code Execution (RCE). This month’s Patch Tuesday release includes fixes for two zero-day vulnerabilities as well, one known to be actively exploited ( CVE-2022-
Tenable
Microsoft’s April 2022 Patch Tuesday Addresses 117 CVEs (CVE-2022-24521)
blogs_tenable·2022-04-12·CVSS 7.8
[HIGH] Microsoft’s April 2022 Patch Tuesday Addresses 117 CVEs (CVE-2022-24521)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical. | Qualys
blogs_qualys·2022-04-12·CVSS 8.8
[HIGH] April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- Notable Microsoft Vulnerabilities Patched
- Notable Adobe Vulnerabilities Patched
- About Qualys Patch Tuesday
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Monthly Webinar Series: This Month in Vulnerabilities & Patches
- Join the Webinar This Month in Vulnerabilities & Patches
- Contributor
## Microsoft Patch Tuesday Summary
Microsoft has fixed 145 vulnerabilities, including 17 Microsoft Edge vulnerabilities, in the April 2022 update, with ten classified as critical as they allow Remote Code Execution (RCE). This month’s Patch Tuesday release includes fixes for two zero-day vulnerabilities as well, one known to be actively exploited
Zscaler
Zscaler found Windows security vulnerabilities | 04-12-2022
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler found Windows security vulnerabilities | 04-12-2022
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Crowdstrike
April 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] April 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2022-04-15
Published
2022-04-25
Added to CISA KEV
Exploited in the wild