CVE-2021-41379mediumunder attackransomwareCWE-59

CVE-2021-41379: medium-severity vulnerability in Microsoft Windows 10 Version 1507

Windows Installer Elevation of Privilege Vulnerability

Published · Updated

68Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 5.5epss 19%
from disclosure to weapon22 days
Published on NVDNov 10
1st PoC+22d
CISA KEV+113d
exploitation probability
19%top 3% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-03-17

Apply updates per vendor instructions.

In short

Windows Installer has a vulnerability that allows an attacker with limited user privileges to gain elevated administrative access on a Windows system. An attacker can exploit this by manipulating installer files or processes to run malicious code with higher privileges.

Technical detail

CWE-59 (Improper Link Resolution Before File Access) in Windows Installer allows privilege escalation via symbolic link or directory junction manipulation during the installation process. An attacker with local user access can redirect installer operations to execute arbitrary code with SYSTEM privileges by exploiting insecure temporary file handling.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Windows Installer Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.