CVE-2022-21919: Windows User Profile Service Elevation of Privilege Vulnerability
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
Other sources
Windows User Profile Service Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20246Patch KB5009595 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.25829Patch KB5009621 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23584Patch KB5009619 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21349Patch KB5009601 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20246Patch KB5009624 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4886Patch KB5009546 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19177Patch KB5009585 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.1466Patch KB5009543 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1466Patch KB5009543 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1466Patch KB5009543 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.434Patch KB5009566 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.469Patch KB5009555 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.2037Patch KB5009545 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2452Patch KB5009557
Event History
Frequently Asked Questions
What is CVE-2022-21919?
CVE-2022-21919 is a vulnerability in Microsoft Windows User Profile Service that allows for privilege escalation.
Which software is affected by CVE-2022-21919?
Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows 7, Microsoft Windows 8.1, Microsoft Windows Server, and Microsoft Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016, and 2019 are affected by CVE-2022-21919.
How severe is CVE-2022-21919?
CVE-2022-21919 has a severity rating of high (7 out of 10).
How can I fix CVE-2022-21919?
Apply the latest security updates and patches provided by Microsoft to mitigate CVE-2022-21919.
Where can I find more information about CVE-2022-21919?
You can find more information about CVE-2022-21919 on the Microsoft Security Guidance advisory page: [link](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-21919).