ZeroHour

CVE-2021-34486

KEVmass

Use-after-free privilege escalation in Windows Event Tracing (Windows 10 / Server)

CISA: Microsoft Windows Event Tracing Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
9%p95
Published
()
KEV added
AI analysis

CVE-2021-34486 is a use-after-free flaw (CWE-416) in the Windows Event Tracing (ETW) component of Windows 10 and Windows Server. An attacker who can already run low-privileged code on a target system can trigger improper memory reuse in ETW to execute code with elevated privileges, with no user interaction required (CVSS 3.1: 7.8, AV:L/AC:L/PR:L/UI:N). Successful exploitation yields privileged, likely SYSTEM-level, control of the host, which adversaries typically chain with other access for full system compromise. The affected releases span Windows 10 versions 1809, 1909, 2004, 20H2 and 21H1, plus Windows Server 2019, 2004 and 20H2. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28, confirming exploitation in the wild; CISA lists ransomware use as unknown and no public proof-of-concept is known.

What to do: Apply Microsoft's security updates per vendor instructions (the CISA-required action) for all affected Windows 10 and Windows Server versions, or upgrade branches that are no longer serviced. Because exploitation requires local code execution, prioritize hosts where untrusted users or code run, such as workstations, shared systems and remote/terminal servers. Review EDR telemetry for local privilege-escalation activity on systems awaiting patching.

Affected
microsoft Windows 101809
microsoft Windows 101909
microsoft Windows 102004
microsoft Windows 1020H2
microsoft Windows 1021H1
microsoft Windows Server2019
microsoft Windows Server2004
microsoft Windows Server20H2
Estimated exposure
masshundreds of millions of Windows 10 and Windows Server installations (affected branches covered the bulk of actively serviced Windows systems) — Windows 10 is the dominant desktop OS with hundreds of millions of devices, and the affected branches (1809 through 21H1) plus Windows Server 2019/2004/20H2 covered most of Microsoft's actively serviced installed base when this flaw was…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Event Tracing Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows server 2004, windows server 2019, windows server 20h2
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.