ZeroHour

CVE-2021-36934

KEVmass

Local Privilege Escalation (SeriousSAM/HiveNightmare) in Microsoft Windows 10

CISA: Microsoft Windows SAM Local Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
67%p99
Published
()
KEV added
AI analysis

CVE-2021-36934 is an elevation of privilege vulnerability in Windows caused by overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. A local attacker who already has the ability to execute low-privileged code on a victim system can leverage the misconfigured ACLs to gain arbitrary code execution with SYSTEM privileges, then install programs, view, change or delete data, or create new accounts with full user rights. Affected products per the CPE data are Windows 10 versions 1809, 1909, 2004, 20H2 and 21H1, with related coverage noting the bug impacts all Windows 10 versions released in the past 2.5 years and also references Windows 11. CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-02-10, confirming in-the-wild exploitation, and EPSS assigns a 67.3% probability of exploitation within 30 days (99th percentile). Mitigation is two-step: installing the security update alone is not sufficient — administrators must also manually delete all shadow copies of system files, including the SAM database, per KB5005357.

What to do: Apply Microsoft's security update per vendor instructions, then follow KB5005357 to manually delete all shadow copies of system files (including the SAM database), because the update alone does not fully mitigate the vulnerability. Restrict or verify ACLs on the System32 config directory and shadow-copy access if shadow-copy deletion cannot be done immediately, and prioritize patching given the flaw's listing in CISA's Known Exploited Vulnerabilities Catalog.

Affected
microsoft Windows 101809
microsoft Windows 101909
microsoft Windows 102004
microsoft Windows 1020H2
microsoft Windows 1021H1
microsoft Windows 11referenced in vendor mitigation coverage (Windows 10, 11 SeriousSAM); not enumerated in the CISA CPE list
Estimated exposure
masshundreds of millions of Windows 10 devices (every supported feature update from mid-2018 through mid-2021 is in scope) — Rather than a plugin or site count, this estimate is driven by the Windows 10 installed base: versions 1809 through 21H1 span roughly 2.5 years of the dominant desktop OS, and Windows 10 runs on the majority of the world's 1B+ Windows PCs,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have the ability to execute code on a victim system to exploit this vulnerability. After installing this security update, you must manually delete all shadow copies of system files, including the SAM database, to fully mitigate this vulnerabilty. Simply installing this security update will not fully mitigate this vulnerability. See KB5005357- Delete Volume Shadow Copies.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news