ZeroHour

CVE-2021-34484

KEVmass

Privilege Escalation in Microsoft Windows User Profile Service (CWE-269)

CISA: Microsoft Windows User Profile Service Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
22%p98
Published
()
KEV added
AI analysis

CVE-2021-34484 is a privilege escalation flaw in the Microsoft Windows User Profile Service in which the service improperly handles user profiles, allowing an attacker who can already run code on a local machine to gain elevated privileges. The flaw is triggered by local execution, meaning an attacker must first obtain a foothold on the target system — for example via malware, a compromised account, or a chained remote code execution bug — and then exploit the User Profile Service to elevate. By escalating privileges, an attacker can typically gain SYSTEM-level access, take full control of the host, disable security tooling, and move laterally across a network, which makes this bug a common step in ransomware and broader intrusion chains. All Microsoft Windows deployments are in scope per CISA, though only unpatched systems are practically at risk. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2022-03-31 with a required action to apply vendor updates, and EPSS assigns a 21.8% probability of exploitation within 30 days (97th percentile), indicating elevated near-term risk.

What to do: Apply Microsoft's security updates for the User Profile Service privilege escalation per vendor instructions, as required by CISA's KEV catalog entry. Because this is a local privilege escalation often chained with initial-access or malware infections, prioritize hosts where untrusted users can execute code — workstations, RDP/session hosts, and VDI — and confirm the applicable August 2021 (or later) cumulative update is installed. Use EDR telemetry and Windows Event Logs (User Profile Service activity) to check for signs of prior exploitation on systems that were unpatched since before the fix was released.

Affected
Microsoft Windows
Estimated exposure
masshundreds of millions of Windows devices and installations worldwide; effectively every unpatched Windows endpoint and server — Windows is the dominant desktop and server operating system with roughly 1.4 billion active devices and the vast majority of enterprise endpoint fleets, so the potential install base is on the order of hundreds of millions, limited only by…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows User Profile Service Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 7, windows 8.1, windows rt 8.1, windows server 2004, windows server 2008
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news