CVE-2021-1729: Microsoft Windows Setup Directory Junction Denial-of-Service Vulnerability
Windows Update Stack Setup Elevation of Privilege Vulnerability
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within Windows Setup. By creating a directory junction, an attacker can abuse Windows Setup to delete a file. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.867Patch KB5000802 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1440Patch KB5000808 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.1817Patch KB5000822 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17134.2087Patch KB5000809
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1729?
CVE-2021-1729 has been classified as a critical elevation of privilege vulnerability.
How do I fix CVE-2021-1729?
To fix CVE-2021-1729, apply the latest security updates from Microsoft available for affected Windows versions.
Which versions of Windows are affected by CVE-2021-1729?
CVE-2021-1729 affects multiple versions of Windows 10 and Windows Server, specifically those listed in the Microsoft advisory.
Can CVE-2021-1729 be exploited remotely?
No, CVE-2021-1729 requires local access to the device for exploitation.
What type of attack does CVE-2021-1729 enable?
CVE-2021-1729 enables local attackers to elevate privileges and potentially cause a denial-of-service condition.