← back
CVE-2021-34484

Windows User Profile Service Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 14.4%● KEV
In short

A flaw in Windows User Profile Service allows an attacker with local access to gain elevated privileges and take control of the system. This is dangerous because it lets ordinary users become administrators without proper authorization.

Technical detail

Local privilege escalation vulnerability in Windows User Profile Service exploitable by authenticated local users. The vulnerability allows arbitrary code execution with SYSTEM privileges through improper permission handling in profile-related operations.

Summary generated and translated by AI from the official description.
Windows User Profile Service Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →