Windows User Profile Service Elevation of Privilege Vulnerability
References
Configurations
Configuration 1 (hide)
|
History
14 Nov 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
21 Dec 2023, 01:15
Type | Values Removed | Values Added |
---|---|---|
Summary | Windows User Profile Service Elevation of Privilege Vulnerability |
08 Aug 2023, 14:21
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-59 |
19 Jan 2022, 13:59
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-269 | |
CVSS |
v2 : v3 : |
v2 : 7.2
v3 : 7.8 |
References | (MISC) https://www.zerodayinitiative.com/advisories/ZDI-22-050/ - Third Party Advisory | |
References | (MISC) https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-21895 - Patch, Vendor Advisory | |
CPE | cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_server:20h2:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server:2022:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:rt:*:*:* cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:-:*:*:* cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_10:21h2:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* |
13 Jan 2022, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
11 Jan 2022, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-01-11 21:15
Updated : 2024-11-14 21:15
NVD link : CVE-2022-21895
Mitre link : CVE-2022-21895
CVE.ORG link : CVE-2022-21895
JSON object : View
Products Affected
microsoft
- windows_server_2012
- windows_8.1
- windows_server_2016
- windows_server
- windows_server_2019
- windows_10
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')