Junglewise Threat Intelligence

CVE-2021-34486: Microsoft Windows Event Tracing Privilege Escalation Vulnerability

CVE-2021-34486 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Windows, Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows Server 2019. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability (CWE-416) in Microsoft Windows Event Tracing allows a local attacker to gain elevated privileges. The vulnerability enables an authenticated user to execute code with higher permissions than originally granted.

Affected products

  • Microsoft Windows 10 1809, 1909, 2004, 20H2, 21H1
  • Microsoft Windows Server 2019 -
  • Microsoft Windows Server 2016 2004, 20H2

Timeline

  • 2021-08-12: disclosed: NVD Published Date
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-08-12: patched: Microsoft released security updates

Related threats