CVE-2021-26862: Microsoft Windows Installer Service Directory Junction Privilege Escalation Vulnerability
Windows Installer Elevation of Privilege Vulnerability
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Windows Installer Service. By creating a directory junction, an attacker can abuse the service to create an arbitrary file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.19968Patch KB5000853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23298Patch KB5000840 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21070Patch KB5000856 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.24566Patch KB5000851 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.19968Patch KB5000848 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4283Patch KB5000803 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.18874Patch KB5000807 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.867Patch KB5000802 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1440Patch KB5000808 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.1817Patch KB5000822 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17134.2087Patch KB5000809
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26862?
CVE-2021-26862 is rated as important, allowing local attackers to escalate privileges on affected installations.
How do I fix CVE-2021-26862?
You can fix CVE-2021-26862 by applying the appropriate security updates provided by Microsoft.
Which versions of Windows are affected by CVE-2021-26862?
CVE-2021-26862 affects multiple versions of Windows, including Windows 7, Windows 10, and various Windows Server editions.
Can CVE-2021-26862 be exploited remotely?
No, CVE-2021-26862 requires local access to the system to exploit the vulnerability.
What type of vulnerability is CVE-2021-26862?
CVE-2021-26862 is classified as an elevation of privilege vulnerability in the Windows Installer.