KEV · Actively exploited
CVE-2022-21919
HIGH 7.0
KEV
Windows User Profile Service Elevation of Privilege Vulnerability
EPSS
0.31%
above median
percentile 54.4%
CISA Known Exploited Vulnerability
- Added to KEV
- 2022-04-25
- Remediation deadline
- 2022-05-16
- Required action
- Apply updates per vendor instructions.
- Ransomware
- No
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Fixed in Windows Server 2022 (Server Core installation) 10.0.20348.469 Windows Server 2022 10.0.20348.469 Windows Server 2019 (Server Core installation) 10.0.17763.2452 Windows Server 2019 10.0.17763.2452 Windows Server 2016 (Server Core installation) 10.0.14393.4886 Windows Server 2016 10.0.14393.4886 Windows 11 21H2 · 2021-H2 10.0.22000.434 Windows 10 21H2 · 2021-H2 10.0.19044.1466 Windows 10 21H1 · 2021-H1 10.0.19043.1466 Windows 10 20H2 · 2020-H2 10.0.19042.1466 Windows 10 1909 · 2019-09 10.0.18363.2037 Windows 10 1809 · 2018-09 10.0.17763.2452 Windows 10 1607 · 2016-07 10.0.14393.4886