CVE-2021-36934 Windows Elevation of Privilege Vulnerability

    CVE-2021-36934 Windows Elevation of Privilege Vulnerability

    CVE-2021-36934 Windows Elevation of Privilege Vulnerability

    HiveVulnerability - Windows 10 version 1809 and higher

    Last Updated: 21 Jul 2021 at 12:35

    Executive Summary

    An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

    An attacker must have the ability to execute code on a victim system to exploit this vulnerability.

    We will update this CVE with mitigations and workarounds as our investigation progresses.

    FAQ

    No versions of Windows are listed in the Security Updates table. Are all versions vulnerable?

    So far, we can confirm that this issue affects Windows 10 version 1809 and newer client operating systems. We will update this CVE as we continue our investigation. If you wish to be notified when updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this CVE. See Microsoft Technical Security Notifications.



    Read more: https://msrc.microsoft.com/update-gu...CVE-2021-36934
    Brink's Avatar Posted By: Brink
    20 Jul 2021


  1. Posts : 750
    Windows 10 Pro 64-bits
       #1

    System restore is disabled on my systems:

    CVE-2021-36934 Windows Elevation of Privilege Vulnerability-vss_shadow.png

    Running the MS recommended script as workaround for this vulnerability results in an error:

    CVE-2021-36934 Windows Elevation of Privilege Vulnerability-icalcs.png

    Any reason why this error showing up on my system?

    TIA...
      My Computer


  2. Posts : 171
    Windows 10 Ent, Pro & Home
       #2

    When I try to access \%windir%\system32\config folder I am asked to give Admin permission to access this folder. That is why the command fails. I am going to leave the folder alone, my guess is someone has changed the perms on that folder and thinks there is an issue. But could be, because you are running VSS. I am not running VSS.
      My Computer


  3. Posts : 750
    Windows 10 Pro 64-bits
       #3

    wyldman68 said:
    When I try to access \%windir%\system32\config folder I am asked to give Admin permission to access this folder. That is why the command fails. I am going to leave the folder alone, my guess is someone has changed the perms on that folder and thinks there is an issue. But could be, because you are running VSS. I am not running VSS.
    Yes, both the command line and PowerShell had admin access. Just to be certain, logged out and logged in as an admin, but it did not make a difference. The error message states, that the file is not found.

    The VSS service isn't running either; maybe the syntax is incorrect?
      My Computer


  4. Posts : 67
    Windows 10
       #4

    In PowerShell try running this command "icacls $env:windir\system32\config\*.* /inheritance:e"
    Variables in PowerShell work differently than in a cmd line.


      My Computer


  5. Posts : 36
    Windows 10 64 bit
       #5

    you have to run both the Command Prompt and PowerShell in administrator mode. For Command Prompt go to the start menu, windows system folder and right-click on the Command Prompt chose more than run as administrator.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 19:22.
Find Us




Windows 10 Forums