CVE-2021-26887: Microsoft Windows Folder Redirection Elevation of Privilege Vulnerability

Published Mar 9, 2021
·
Updated

An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited the vulnerability would be able to begin redirecting another user's personal data to a created folder. To exploit the vulnerability, an attacker can create a new folder under the Folder Redirection root path and create a junction on a newly created User folder. When the new user logs in, Folder Redirection would start redirecting to the folder and copying personal data. This elevation of privilege vulnerability can only be addressed by reconfiguring Folder Redirection with Offline files and restricting permissions, and NOT via a security update for affected Windows Servers. See the FAQ section of this CVE for configuration guidance.

Other sources

Microsoft Windows Folder Redirection Elevation of Privilege Vulnerability

Affected Software

59 affected componentsFixes available
Microsoft Windows 10
Microsoft Windows 10=20h2
Microsoft Windows 10=1607
Microsoft Windows 10=1803
Microsoft Windows 10=1809
Microsoft Windows 10=1909
Microsoft Windows 10=2004
Microsoft Windows 7=sp1
Microsoft Windows 8.1
Microsoft Windows RT 8.1
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016
Microsoft Windows Server 2016=20h2
Microsoft Windows Server 2016=1909
Microsoft Windows Server 2016=2004
Microsoft Windows Server 2019
Microsoft Windows Server 2012<6.2.9200.23298
6.2.9200.23298
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2012<6.2.9200.23298
6.2.9200.23298
Microsoft Windows Server 2012 R2
Microsoft Windows RT 8.1
Microsoft Windows 8.1 for x64-based systems
Microsoft Windows 8.1 for 32-bit systems
Microsoft Windows Server 2008
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2008
Microsoft Windows Server 2008
Microsoft Windows 7
Microsoft Windows Server 2016
Microsoft Windows Server 2016
Microsoft Windows 7
Microsoft Windows 10=1607
Microsoft Windows 10=1607
Microsoft Windows 10
Microsoft Windows Server=1909
Microsoft Windows 10
Microsoft Windows 10=1909
Microsoft Windows 10=1809
Microsoft Windows 10=1909
Microsoft Windows Server 2019
Microsoft Windows 10=1809
Microsoft Windows Server 2019
Microsoft Windows 10=1809
Microsoft Windows 10=1803
Microsoft Windows 10=1803
Microsoft Windows 10=1803
Microsoft Windows 10=1909
Microsoft Windows 10=20H2
Microsoft Windows Server=20H2
Microsoft Windows 10=20H2
Microsoft Windows Server=2004
Microsoft Windows 10=2004
Microsoft Windows 10=2004
Microsoft Windows 10=2004

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.2.9200.23298Patch KB5000840
  2. Configuration

    Reconfigure Folder Redirection using Offline files and restrict permissions (per the CVE FAQ configuration guidance), since the vulnerability cannot be addressed via a security update for affected Windows Servers.

    Microsoft Windows Group Policy Folder Redirection Folder Redirection reconfiguration to use Offline Files and restrict permissions = Reconfigure Folder Redirection with Offline files; restrict permissions as per CVE FAQ guidance
  3. Compensating control

    If Folder Redirection file server is co-located with Terminal Server, add compensating controls to prevent an attacker from exploiting by creating a junction under the Folder Redirection root/user folders (e.g., restrict filesystem permissions on the Folder Redirection root path and deny creation of junctions where applicable), aligned with the restriction-permissions guidance in the CVE FAQ.

Event History

Mar 9, 2021
CVE Published
via Microsoft·04:00 PM
Data Sourced
via Microsoft·04:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·04:00 PM
Affected Software
Updated
via Microsoft·04:00 PM
Description
Mar 11, 2021
CVE Published
via MITRE·03:42 PM
Data Sourced
via MITRE·03:42 PM
DescriptionSeverity
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2021-26887?

CVE-2021-26887 has a severity rating of Important as it allows elevation of privilege in Windows.

2

How do I fix CVE-2021-26887?

To fix CVE-2021-26887, apply the latest security updates released by Microsoft for your affected Windows version.

3

Which Windows versions are affected by CVE-2021-26887?

CVE-2021-26887 affects multiple versions of Microsoft Windows including Windows 10, Windows Server 2008, Windows Server 2016, and Windows Server 2019.

4

What type of vulnerability is CVE-2021-26887?

CVE-2021-26887 is an elevation of privilege vulnerability due to improper folder redirection configuration.

5

Can CVE-2021-26887 be exploited remotely?

CVE-2021-26887 requires local access to exploit, but it could enable an attacker to gain higher privileges on the system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203