ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews1

Unpatched Unauthorized File Read Vulnerability Affects Microsoft Windows OS

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-24084
Windows Mobile Device Management Information Disclosure Vulnerability

Windows Mobile Device Management Information Disclosure Vulnerability

NVD description · AI analysis pending
5.53%
  • microsoft windows 10
  • microsoft windows server 2016
  • microsoft windows server 2019
CVE-2021-34484
Privilege Escalation in Microsoft Windows User Profile Service (CWE-269)

CVE-2021-34484 is a privilege escalation flaw in the Microsoft Windows User Profile Service in which the service improperly handles user profiles, allowing an attacker who can already run code on a local machine to gain elevated privileges. The flaw is triggered by local execution, meaning an attacker must first obtain a foothold on the target system — for example via malware, a compromised account, or a chained remote code execution bug — and then exploit the User Profile Service to elevate. By escalating privileges, an attacker can typically gain SYSTEM-level access, take full control of the host, disable security tooling, and move laterally across a network, which makes this bug a common step in ransomware and broader intrusion chains. All Microsoft Windows deployments are in scope per CISA, though only unpatched systems are practically at risk. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2022-03-31 with a required action to apply vendor updates, and EPSS assigns a 21.8% probability of exploitation within 30 days (97th percentile), indicating elevated near-term risk.

Do: Apply Microsoft's security updates for the User Profile Service privilege escalation per vendor instructions, as required by CISA's KEV catalog entry. Because this is a local privilege escalation often chained with initial-access or malware infections, prioritize hosts where untrusted users can execute code — workstations, RDP/session hosts, and VDI — and confirm the applicable August 2021 (or later) cumulative update is installed. Use EDR telemetry and Windows Event Logs (User Profile Service activity) to check for signs of prior exploitation on systems that were unpatched since before the fix was released.

7.822% KEV
  • Microsoft Windows
masshundreds of millions of Windows devices and installations worldwide; effectively every unpatched Windows endpoint and server
CVE-2021-41379
Local Privilege Escalation in Microsoft Windows Installer (CVE-2021-41379)

CVE-2021-41379 is an elevation of privilege flaw in the Microsoft Windows Installer service, rooted in improper link resolution before file access (CWE-59), where the privileged installer can be made to follow attacker-controlled file links. It is triggered by a local, low-privileged user who initiates a Windows Installer operation and manipulates the links or paths the installer resolves while running with elevated rights. A successful attacker gains elevated (SYSTEM-level) privileges on the affected machine, a common post-breach step in ransomware chains. The affected list spans essentially the entire supported Windows install base: Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 21H1, Windows 11 21H2, and Windows Server 2004. Exploitation is confirmed in the wild - CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-03-03 with known ransomware use, and EPSS places it in the 97th percentile (19.4% probability of exploitation in 30 days) despite no public PoC being known.

Do: Apply Microsoft's security update for CVE-2021-41379 (delivered via the November 2021 monthly Windows cumulative updates) to all affected Windows 7/8.1/RT 8.1/10/11 and Windows Server systems and keep cumulative updates current. Because CISA's KEV entry cites known ransomware use and the flaw is exploitable by any local standard user, prioritize patching multi-user hosts, servers, and endpoints that allow standard (non-admin) logons; as an interim mitigation, restrict local logon rights on unpatched machines and ensure users operate without administrative privileges.

5.520% KEV ransomware
  • Microsoft Windows 10 1507 all supported builds at disclosure (pre-patch)
  • Microsoft Windows 10 1607 all supported builds at disclosure (pre-patch)
  • Microsoft Windows 10 1809 all supported builds at disclosure (pre-patch)
  • +9 more
mass≈1 billion+ Windows installations (effectively the entire supported Windows client and server install base)
Full article441 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananNov 30, 2021

Unofficial patches have been issued to remediate an improperly patched Windows security vulnerability that could allow information disclosure and local privilege escalation (LPE) on vulnerable systems.

Tracked as CVE-2021-24084 (CVSS score: 5.5), the flaw concerns an information disclosure vulnerability in the Windows Mobile Device Management component that could enable an attacker to gain unauthorized file system access and read arbitrary files.

Security researcher Abdelhamid Naceri was credited with discovering and reporting the bug in October 2020, prompting Microsoft to address the issue as part of its February 2021 Patch Tuesday updates.

But as observed by Naceri in June 2021, not only could the patch be bypassed to achieve the same objective, the researcher this month found that the incompletely patched vulnerability could also be exploited to gain administrator privileges and run malicious code on Windows 10 machines running the latest security updates.

"Namely, as HiveNightmare/SeriousSAM has taught us, an arbitrary file disclosure can be upgraded to local privilege escalation if you know which files to take and what to do with them," 0patch co-founder Mitja Kolsek said in a post last week.

However, it's worth noting that the vulnerability can be exploited to accomplish privilege escalation only under specific circumstances, namely when the system protection feature is enabled on C: Drive and at least one local administrator account is set up on the computer.

Neither Windows Servers nor systems running Windows 11 are affected by the vulnerability, but the following Windows 10 versions are impacted —

  • Windows 10 v21H1 (32 & 64 bit) updated with November 2021 Updates
  • Windows 10 v20H2 (32 & 64 bit) updated with November 2021 Updates
  • Windows 10 v2004 (32 & 64 bit) updated with November 2021 Updates
  • Windows 10 v1909 (32 & 64 bit) updated with November 2021 Updates
  • Windows 10 v1903 (32 & 64 bit) updated with November 2021 Updates
  • Windows 10 v1809 (32 & 64 bit) updated with May 2021 Updates

CVE-2021-24084 is also the third zero-day Windows vulnerability to rear its head again as a consequence of an incomplete patch issued by Microsoft. Earlier this month, 0patch shipped unofficial fixes for a local privilege escalation vulnerability (CVE-2021-34484) in the Windows User Profile Service that enables attackers to gain SYSTEM privileges.

Then last week, Naceri disclosed details of another zero-day flaw in the Microsoft Windows Installer service (CVE-2021-41379) that could be bypassed to achieve elevated privileges on devices running the latest Windows versions, including Windows 10, Windows 11, and Windows Server 2022.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/11/unpatched-unauthorized-file-read.html