Junglewise Threat Intelligence

CVE-2021-36934: Microsoft Windows SAM Local Privilege Escalation Vulnerability

CVE-2021-36934 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-02-10

Technologies: Microsoft Windows, Microsoft Windows 10 1809. Vendors: Microsoft.

Executive brief

An elevation of privilege vulnerability exists in Microsoft Windows due to overly permissive Access Control Lists (ACLs) on system files, including the Security Accounts Manager (SAM) database. If a Volume Shadow Copy (VSS) is available, a local attacker can read the SAM file to obtain SYSTEM privileges. Full mitigation requires both installing security updates and manually deleting existing shadow copies.

Affected products

  • Microsoft Windows 10 20H2
  • Microsoft Windows 10 21H1
  • Microsoft Windows 10 1809

Timeline

  • 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-02-10: disclosed

Related threats