ZeroHour

CVE-2021-36948

KEVmass1

Privilege Escalation in Microsoft Windows Update Medic Service

CISA: Microsoft Windows Update Medic Service Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
23%p98
Published
()
KEV added
AI analysis

CVE-2021-36948 is an elevation-of-privilege flaw in the Microsoft Windows Update Medic Service (WaaSMedicSvc), the built-in service that keeps Windows Update functioning; Microsoft has not publicly detailed the underlying bug. A local attacker who can execute code on a target machine can abuse the service to elevate their privileges to higher integrity levels, typically SYSTEM, enabling full control of the host such as installing software, modifying accounts, and disabling defenses. Any Windows system running the Windows Update Medic Service is affected; CISA lists the impacted product simply as 'Microsoft Windows' without version detail, and the service ships with Windows 10 and later. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, indicating confirmed exploitation in the wild, with no public proof-of-concept code known and ransomware use undetermined. Microsoft's EPSS model assigns a 26.7% probability of exploitation within 30 days (98th percentile), so patching urgency is high.

What to do: Apply Microsoft's November 2021 Patch Tuesday cumulative updates (per the vendor's advisory) via Windows Update or your patch management platform, prioritizing servers, workstations, and multi-user hosts where local privilege escalation is most damaging. Since CISA lists this in KEV, federal and regulated environments must patch by the catalog deadline; as an interim mitigation, restrict untrusted local code execution and review whether any local accounts show unexpected SYSTEM-level activity.

Affected
Microsoft Windows (systems running the Windows Update Medic Service; Windows 10 and later)CISA lists affected product as 'Microsoft Windows' without version detail; remediated in Microsoft's November 2021 security updates
Estimated exposure
mass≈1 billion+ Windows devices (the Medic Service ships on effectively every Windows 10/11 machine) — The Windows Update Medic Service is present by default on Windows 10 and Windows 11, whose combined install base exceeds one billion devices, so essentially all unpatched Windows endpoints are exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Update Medic Service Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows server 2004, windows server 2019, windows server 20h2
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news