CVE-2021-26866: Microsoft Windows Update Agent Directory Junction Denial-of-Service Vulnerability
Windows Update Service Elevation of Privilege Vulnerability
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within Windows Update Agent. By creating a directory junction, an attacker can abuse Windows Update Agent to delete a directory. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4283Patch KB5000803 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.18874Patch KB5000807 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.867Patch KB5000802 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1440Patch KB5000808 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.1817Patch KB5000822 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17134.2087Patch KB5000809
Event History
Frequently Asked Questions
What is CVE-2021-26866?
CVE-2021-26866 is a vulnerability that allows local attackers to create a denial-of-service condition on affected installations of Microsoft Windows.
How does CVE-2021-26866 work?
The vulnerability is caused by a flaw within the Windows Update Agent that can be exploited by executing low-privileged code on the target system.
What is the severity of CVE-2021-26866?
CVE-2021-26866 has a high severity rating with a severity value of 7.1.
Which versions of Windows are affected by CVE-2021-26866?
Microsoft Windows Server 2019, Windows 10 (version 1809), Windows 10 (version 1909), Windows 10 (version 1803), Windows 10 (version 1607), Windows Server 2016, and Windows 10 (version 2004) are affected by CVE-2021-26866.
How can I fix CVE-2021-26866?
To fix CVE-2021-26866, apply the relevant patch provided by Microsoft, which can be found in the associated URLs.