Unpatched Unauthorized File Read Vulnerability Affects Microsoft Windows OS
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-24084 | Windows Mobile Device Management Information Disclosure Vulnerability Windows Mobile Device Management Information Disclosure Vulnerability NVD description · AI analysis pending | 5.5 | 3% |
| — | ||
| CVE-2021-34484 | Privilege Escalation in Microsoft Windows User Profile Service (CWE-269) CVE-2021-34484 is a privilege escalation flaw in the Microsoft Windows User Profile Service in which the service improperly handles user profiles, allowing an attacker who can already run code on a local machine to gain elevated privileges. The flaw is triggered by local execution, meaning an attacker must first obtain a foothold on the target system — for example via malware, a compromised account, or a chained remote code execution bug — and then exploit the User Profile Service to elevate. By escalating privileges, an attacker can typically gain SYSTEM-level access, take full control of the host, disable security tooling, and move laterally across a network, which makes this bug a common step in ransomware and broader intrusion chains. All Microsoft Windows deployments are in scope per CISA, though only unpatched systems are practically at risk. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2022-03-31 with a required action to apply vendor updates, and EPSS assigns a 21.8% probability of exploitation within 30 days (97th percentile), indicating elevated near-term risk. Do: Apply Microsoft's security updates for the User Profile Service privilege escalation per vendor instructions, as required by CISA's KEV catalog entry. Because this is a local privilege escalation often chained with initial-access or malware infections, prioritize hosts where untrusted users can execute code — workstations, RDP/session hosts, and VDI — and confirm the applicable August 2021 (or later) cumulative update is installed. Use EDR telemetry and Windows Event Logs (User Profile Service activity) to check for signs of prior exploitation on systems that were unpatched since before the fix was released. | 7.8 | 22% | KEV |
| masshundreds of millions of Windows devices and installations worldwide; effectively every unpatched Windows endpoint and server | |
| CVE-2021-41379 | Local Privilege Escalation in Microsoft Windows Installer (CVE-2021-41379) CVE-2021-41379 is an elevation of privilege flaw in the Microsoft Windows Installer service, rooted in improper link resolution before file access (CWE-59), where the privileged installer can be made to follow attacker-controlled file links. It is triggered by a local, low-privileged user who initiates a Windows Installer operation and manipulates the links or paths the installer resolves while running with elevated rights. A successful attacker gains elevated (SYSTEM-level) privileges on the affected machine, a common post-breach step in ransomware chains. The affected list spans essentially the entire supported Windows install base: Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 21H1, Windows 11 21H2, and Windows Server 2004. Exploitation is confirmed in the wild - CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-03-03 with known ransomware use, and EPSS places it in the 97th percentile (19.4% probability of exploitation in 30 days) despite no public PoC being known. Do: Apply Microsoft's security update for CVE-2021-41379 (delivered via the November 2021 monthly Windows cumulative updates) to all affected Windows 7/8.1/RT 8.1/10/11 and Windows Server systems and keep cumulative updates current. Because CISA's KEV entry cites known ransomware use and the flaw is exploitable by any local standard user, prioritize patching multi-user hosts, servers, and endpoints that allow standard (non-admin) logons; as an interim mitigation, restrict local logon rights on unpatched machines and ensure users operate without administrative privileges. | 5.5 | 20% | KEV ransomware |
| mass≈1 billion+ Windows installations (effectively the entire supported Windows client and server install base) |
Full article441 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananNov 30, 2021
Unofficial patches have been issued to remediate an improperly patched Windows security vulnerability that could allow information disclosure and local privilege escalation (LPE) on vulnerable systems.
Tracked as CVE-2021-24084 (CVSS score: 5.5), the flaw concerns an information disclosure vulnerability in the Windows Mobile Device Management component that could enable an attacker to gain unauthorized file system access and read arbitrary files.
Security researcher Abdelhamid Naceri was credited with discovering and reporting the bug in October 2020, prompting Microsoft to address the issue as part of its February 2021 Patch Tuesday updates.
But as observed by Naceri in June 2021, not only could the patch be bypassed to achieve the same objective, the researcher this month found that the incompletely patched vulnerability could also be exploited to gain administrator privileges and run malicious code on Windows 10 machines running the latest security updates.
"Namely, as HiveNightmare/SeriousSAM has taught us, an arbitrary file disclosure can be upgraded to local privilege escalation if you know which files to take and what to do with them," 0patch co-founder Mitja Kolsek said in a post last week.
However, it's worth noting that the vulnerability can be exploited to accomplish privilege escalation only under specific circumstances, namely when the system protection feature is enabled on C: Drive and at least one local administrator account is set up on the computer.
Neither Windows Servers nor systems running Windows 11 are affected by the vulnerability, but the following Windows 10 versions are impacted —
- Windows 10 v21H1 (32 & 64 bit) updated with November 2021 Updates
- Windows 10 v20H2 (32 & 64 bit) updated with November 2021 Updates
- Windows 10 v2004 (32 & 64 bit) updated with November 2021 Updates
- Windows 10 v1909 (32 & 64 bit) updated with November 2021 Updates
- Windows 10 v1903 (32 & 64 bit) updated with November 2021 Updates
- Windows 10 v1809 (32 & 64 bit) updated with May 2021 Updates
CVE-2021-24084 is also the third zero-day Windows vulnerability to rear its head again as a consequence of an incomplete patch issued by Microsoft. Earlier this month, 0patch shipped unofficial fixes for a local privilege escalation vulnerability (CVE-2021-34484) in the Windows User Profile Service that enables attackers to gain SYSTEM privileges.
Then last week, Naceri disclosed details of another zero-day flaw in the Microsoft Windows Installer service (CVE-2021-41379) that could be bypassed to achieve elevated privileges on devices running the latest Windows versions, including Windows 10, Windows 11, and Windows Server 2022.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/11/unpatched-unauthorized-file-read.html