CVE-2021-26434: Microsoft Visual Studio Incorrect Permission Assignment Privilege Escalation Vulnerability
Visual Studio Elevation of Privilege Vulnerability
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Visual Studio. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Visual Studio installer. The issue results from incorrect permissions set on a resource used by the installer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.9.11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.7.19 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.4.26 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.9.39 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.11.3
Event History
Frequently Asked Questions
What is CVE-2021-26434?
CVE-2021-26434 is a vulnerability in Microsoft Visual Studio that allows local attackers to escalate privileges on affected installations.
How severe is CVE-2021-26434?
CVE-2021-26434 has a severity rating of 7.8, which is considered high.
How can I fix CVE-2021-26434?
To fix CVE-2021-26434, you should update the affected installations of Microsoft Visual Studio to the patched versions.
Where can I find more information about CVE-2021-26434?
You can find more information about CVE-2021-26434 on the Microsoft Security Response Center website and the Zero Day Initiative advisories.