CVE-2021-26887: Microsoft Windows Folder Redirection Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited the vulnerability would be able to begin redirecting another user's personal data to a created folder. To exploit the vulnerability, an attacker can create a new folder under the Folder Redirection root path and create a junction on a newly created User folder. When the new user logs in, Folder Redirection would start redirecting to the folder and copying personal data. This elevation of privilege vulnerability can only be addressed by reconfiguring Folder Redirection with Offline files and restricting permissions, and NOT via a security update for affected Windows Servers. See the FAQ section of this CVE for configuration guidance.
Other sources
Microsoft Windows Folder Redirection Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23298Patch KB5000840 - Configuration
Reconfigure Folder Redirection using Offline files and restrict permissions (per the CVE FAQ configuration guidance), since the vulnerability cannot be addressed via a security update for affected Windows Servers.
Microsoft Windows Group Policy Folder Redirection Folder Redirection reconfiguration to use Offline Files and restrict permissions = Reconfigure Folder Redirection with Offline files; restrict permissions as per CVE FAQ guidance - Compensating control
If Folder Redirection file server is co-located with Terminal Server, add compensating controls to prevent an attacker from exploiting by creating a junction under the Folder Redirection root/user folders (e.g., restrict filesystem permissions on the Folder Redirection root path and deny creation of junctions where applicable), aligned with the restriction-permissions guidance in the CVE FAQ.
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26887?
CVE-2021-26887 has a severity rating of Important as it allows elevation of privilege in Windows.
How do I fix CVE-2021-26887?
To fix CVE-2021-26887, apply the latest security updates released by Microsoft for your affected Windows version.
Which Windows versions are affected by CVE-2021-26887?
CVE-2021-26887 affects multiple versions of Microsoft Windows including Windows 10, Windows Server 2008, Windows Server 2016, and Windows Server 2019.
What type of vulnerability is CVE-2021-26887?
CVE-2021-26887 is an elevation of privilege vulnerability due to improper folder redirection configuration.
Can CVE-2021-26887 be exploited remotely?
CVE-2021-26887 requires local access to exploit, but it could enable an attacker to gain higher privileges on the system.