{"cveID":"CVE-2022-26904","vendorProject":"Microsoft","product":"Windows","vulnerabilityName":"Microsoft Windows User Profile Service Privilege Escalation Vulnerability","dateAdded":"2022-04-25","shortDescription":"Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-05-16","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2022-26904","cwes":["CWE-362"],"year":2022,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2022-26904","technique":"T1078","technique_name_at_mapping":"Valid Accounts","mapping_type":"exploitation_technique","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an adversary who has already gained local access to the victim system. To exploit this vulnerability, the adversary needs to already have access to the system and must also \"win a race condition\". If successfully exploited, the adversary would gain elevated privileges on the victim system. \n\nThis vulnerability has been identified as exploited in the wild; however, technical exploitation details have not been publicly shared. ","references":["https://attackerkb.com/topics/RHSMbN1NQY/cve-2022-26904/vuln-details","https://thehackernews.com/2022/04/microsoft-issues-patches-for-2-windows.html","https://www.covertswarm.com/post/multiple-windows-zero-days-cve-2022-24521-cve-2022-26904-and-cve-2022-26809","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26904"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-26904","technique":"T1068","technique_name_at_mapping":"Exploitation for Privilege Escalation","mapping_type":"primary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an adversary who has already gained local access to the victim system. To exploit this vulnerability, the adversary needs to already have access to the system and must also \"win a race condition\". If successfully exploited, the adversary would gain elevated privileges on the victim system. \n\nThis vulnerability has been identified as exploited in the wild; however, technical exploitation details have not been publicly shared. ","references":["https://attackerkb.com/topics/RHSMbN1NQY/cve-2022-26904/vuln-details","https://thehackernews.com/2022/04/microsoft-issues-patches-for-2-windows.html","https://www.covertswarm.com/post/multiple-windows-zero-days-cve-2022-24521-cve-2022-26904-and-cve-2022-26809","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26904"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1068","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Privilege Escalation","name_at_mapping":"Exploitation for Privilege Escalation","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":31,"has_detection_strategy":true},{"id":"T1078","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Valid Accounts","name_at_mapping":"Valid Accounts","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":56,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}