Vulnerability record · CVE-2022-21919 · published 11 January 2022
CVE-2022-21919: Windows User Profile Service link-following privilege escalation
Microsoft · Windows 10 1507
CVE-2022-21919 is a link-following (CWE-59) elevation of privilege flaw in the Windows User Profile Service. A local attacker who can create or manipulate a link can cause the service to operate on an unintended target, gaining higher privileges on the host. It affects a broad range of Windows client and server releases, so unpatched fleets carry real exposure.
Description
Windows User Profile Service Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in the CISA KEV catalog with confirmed in-the-wild exploitation and affects a wide set of Windows versions, though it requires local access and high attack complexity.
What it is
CVE-2022-21919 is a link-following (CWE-59) elevation of privilege flaw in the Windows User Profile Service. A local attacker who can create or manipulate a link can cause the service to operate on an unintended target, gaining higher privileges on the host. It affects a broad range of Windows client and server releases, so unpatched fleets carry real exposure.
Impact
Successful exploitation gives the attacker elevated privileges on the affected Windows system, typically SYSTEM-level access depending on the service context. That access can be used to disable defenses, persist, or move laterally.
Attack surface
The CVSS vector is AV:L/AC:H/PR:L/UI:N, so the flaw is reached by local access with low privileges and no user interaction; exploitation complexity is rated high. No network or remote vector is described in the record.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-04-25 with a 2022-05-16 remediation due date, indicating exploitation in the wild. EPSS 30-day probability is about 2.98 percent (86th percentile), and no ransomware campaign use is recorded.
What to do
- Apply the Microsoft updates referenced in the MSRC advisory for CVE-2022-21919 across all listed Windows client and server versions.
- Prioritize internet-facing and high-value servers, then workstations, per the CISA KEV due date.
- Restrict local interactive logon and service account rights so low-privileged users cannot trigger the User Profile Service path.
- Monitor for and remove unexpected symbolic links or reparse points in user profile and service-writable directories.
- Verify patch coverage with vulnerability scanning against the affected Windows builds.
Detection
- Alert on creation of symbolic links or reparse points in user profile, temp, and service-writable paths.
- Monitor process creation where a low-privileged parent spawns a high-integrity or SYSTEM child process.
- Audit User Profile Service activity and correlate with unusual file operations on profile directories.
- Track Windows event logs for privilege escalation indicators and unexpected token or integrity-level changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-21919 to the Known Exploited Vulnerabilities catalog on 25 April 2022 as "Microsoft Windows User Profile Service Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 16 May 2022.
Affected products
17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21919 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-21919 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-21919 | US Government Resource |
Track CVE-2022-21919 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-21919), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.