← back
CVE-2022-26904

Windows User Profile Service Elevation of Privilege Vulnerability

CVSS 7 HIGHEPSS 9.8%● KEVCWE-362
In short

A flaw in Windows User Profile Service allows an attacker with local access to gain higher privileges than they should have. This is dangerous because it gives attackers admin-level control over the system.

Technical detail

A race condition (CWE-362) in the Windows User Profile Service permits privilege escalation through timing-based exploitation during profile operations. An attacker with local access can exploit the window between service operations to elevate privileges to SYSTEM level.

Summary generated and translated by AI from the official description.
Windows User Profile Service Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →