Vulnerability record · CVE-2022-26904 · published 15 April 2022
CVE-2022-26904: Windows User Profile Service race condition privilege escalation
Microsoft · Windows 10 1507
CVE-2022-26904 is a race condition (CWE-362) in the Windows User Profile Service that allows elevation of privilege. It affects a broad range of Windows client and server releases, from Windows 7 and Server 2008 through Windows 11 21H2 and Server 2022. Because it is a local privilege escalation in a core Windows component and is listed in CISA KEV, it matters as a post-compromise step to gain higher privileges on a host.
Description
Windows User Profile Service Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a KEV-listed local privilege escalation affecting a very wide range of Windows versions, though exploitation requires an existing foothold on the host.
What it is
CVE-2022-26904 is a race condition (CWE-362) in the Windows User Profile Service that allows elevation of privilege. It affects a broad range of Windows client and server releases, from Windows 7 and Server 2008 through Windows 11 21H2 and Server 2022. Because it is a local privilege escalation in a core Windows component and is listed in CISA KEV, it matters as a post-compromise step to gain higher privileges on a host.
Impact
A local attacker who already has low privileges can exploit the race condition to elevate to a higher integrity level, typically SYSTEM, gaining full control of the affected machine.
Attack surface
The attack is local (AV:L) and requires low privileges (PR:L) with no user interaction (UI:N), meaning an attacker must already have code execution or an interactive session on the target host. It is not remotely reachable over the network.
Exploitation
CVE-2022-26904 is listed in CISA KEV with a due date of 2022-05-16, indicating known exploitation in the wild; EPSS shows a 30-day probability of about 9.6 percent (95th percentile). No ransomware campaign use is recorded in the KEV entry.
What to do
- Apply the Microsoft security updates referenced in the MSRC advisory for all affected Windows versions.
- Prioritize patching of internet-facing and high-value hosts, and treat this as a required remediation under the CISA KEV due date.
- Restrict and monitor local interactive logon and low-privilege code execution paths on endpoints and servers.
- Enforce least privilege and remove unnecessary local administrator or service accounts to limit the value of a successful elevation.
- Track unpatched legacy systems such as Windows 7, 8.1 and Server 2008/2012 that may no longer receive standard updates.
Detection
- Monitor for unexpected creation of SYSTEM-level processes or services originating from low-privilege user sessions.
- Alert on anomalous access or manipulation of user profile registry keys and profile service files.
- Correlate local privilege escalation indicators with prior initial-access activity on the same host.
- Audit Windows event logs for suspicious token or integrity-level changes and unusual service creation around user profile operations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-26904 to the Known Exploited Vulnerabilities catalog on 25 April 2022 as "Microsoft Windows User Profile Service Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 16 May 2022.
Affected products
17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26904 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26904 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26904 | US Government Resource |
Track CVE-2022-26904 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-26904), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.