CVE-2021-34486
KEVmassUse-after-free privilege escalation in Windows Event Tracing (Windows 10 / Server)
CISA: Microsoft Windows Event Tracing Privilege Escalation Vulnerability
CVE-2021-34486 is a use-after-free flaw (CWE-416) in the Windows Event Tracing (ETW) component of Windows 10 and Windows Server. An attacker who can already run low-privileged code on a target system can trigger improper memory reuse in ETW to execute code with elevated privileges, with no user interaction required (CVSS 3.1: 7.8, AV:L/AC:L/PR:L/UI:N). Successful exploitation yields privileged, likely SYSTEM-level, control of the host, which adversaries typically chain with other access for full system compromise. The affected releases span Windows 10 versions 1809, 1909, 2004, 20H2 and 21H1, plus Windows Server 2019, 2004 and 20H2. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28, confirming exploitation in the wild; CISA lists ransomware use as unknown and no public proof-of-concept is known.
What to do: Apply Microsoft's security updates per vendor instructions (the CISA-required action) for all affected Windows 10 and Windows Server versions, or upgrade branches that are no longer serviced. Because exploitation requires local code execution, prioritize hosts where untrusted users or code run, such as workstations, shared systems and remote/terminal servers. Review EDR telemetry for local privilege-escalation activity on systems awaiting patching.
| microsoft Windows 10 | 1809 |
| microsoft Windows 10 | 1909 |
| microsoft Windows 10 | 2004 |
| microsoft Windows 10 | 20H2 |
| microsoft Windows 10 | 21H1 |
| microsoft Windows Server | 2019 |
| microsoft Windows Server | 2004 |
| microsoft Windows Server | 20H2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Event Tracing Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows server 2004, windows server 2019, windows server 20h2
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.