ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz1

After failed fix, researcher releases exploit for Windows EoP flaw (CVE-2021-41379)

mediumVulnerabilityimportance 35CVE-2021-41379

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-41379
Local Privilege Escalation in Microsoft Windows Installer (CVE-2021-41379)

CVE-2021-41379 is an elevation of privilege flaw in the Microsoft Windows Installer service, rooted in improper link resolution before file access (CWE-59), where the privileged installer can be made to follow attacker-controlled file links. It is triggered by a local, low-privileged user who initiates a Windows Installer operation and manipulates the links or paths the installer resolves while running with elevated rights. A successful attacker gains elevated (SYSTEM-level) privileges on the affected machine, a common post-breach step in ransomware chains. The affected list spans essentially the entire supported Windows install base: Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 21H1, Windows 11 21H2, and Windows Server 2004. Exploitation is confirmed in the wild - CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-03-03 with known ransomware use, and EPSS places it in the 97th percentile (19.4% probability of exploitation in 30 days) despite no public PoC being known.

Do: Apply Microsoft's security update for CVE-2021-41379 (delivered via the November 2021 monthly Windows cumulative updates) to all affected Windows 7/8.1/RT 8.1/10/11 and Windows Server systems and keep cumulative updates current. Because CISA's KEV entry cites known ransomware use and the flaw is exploitable by any local standard user, prioritize patching multi-user hosts, servers, and endpoints that allow standard (non-admin) logons; as an interim mitigation, restrict local logon rights on unpatched machines and ensure users operate without administrative privileges.

5.520% KEV ransomware
  • Microsoft Windows 10 1507 all supported builds at disclosure (pre-patch)
  • Microsoft Windows 10 1607 all supported builds at disclosure (pre-patch)
  • Microsoft Windows 10 1809 all supported builds at disclosure (pre-patch)
  • +9 more
mass≈1 billion+ Windows installations (effectively the entire supported Windows client and server install base)
Full article305 words · extracted from helpnetsecurity.com · click to collapse

A local elevation of privilege vulnerability (CVE-2021-41379) in the Windows Installer that Microsoft supposedly fixed on November 2021 Patch Tuesday is, according to its discoverer, still exploitable.

CVE-2021-41379

What’s more, it is already being leveraged by malware developers.

About the flaw and the exploit

Abdelhamid Naceri, who reported the flaw through the Trend Micro Zero Day Initiative, has analyzed the patch for CVE-2021-41379 and found that the bug was “not fixed correctly.”

So he created and made available on GitHub a reliable proof-of-concept exploit (dubbed “InstallerFileTakeOver”) that – others have confirmed – works on fully patched Windows 10, 11, and Windows Server 2022.

Naceri says that the PoC exploit overwrites Microsoft Edge Elevation Service DACL (discretionary access control list) and copies itself to the service location and executes it to gain elevated privileges.

For the exploit to work, an attacker must already have access to the targeted Windows machine and Microsoft Edge must be installed on it.

Risk mitigation

There is currently no official workaround to mitigate the risk posed by this flaw and its failed patch. Any attempt to patch the binary directly will break Windows Installer, Naceri notes, so users’ and admins’ best bet is to wait for Microsoft to come up with a new patch that (ideally) actually works.

In the meantime, Jaeson Schultz, Technical Leader for Cisco Talos Intelligence Group, has shared that they’ve already detected malware samples in the wild that are attempting to take advantage of this vulnerability.

“Since the volume is low, this is likely people working with the proof of concept code or testing for future campaigns. This is just more evidence on how quickly adversaries work to weaponize a publicly available exploit,” he told Bleeping Computer.

Until Microsoft delivers a fix, enterprises can use the Snort rules provided by Cisco to detect attacks targeting CVE-2021-41379.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/11/24/cve-2021-41379/