CVE-2021-26889: Microsoft Windows Setup Directory Junction Privilege Escalation Vulnerability
Windows Update Stack Elevation of Privilege Vulnerability
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within Windows Setup. By creating a directory junction, an attacker can abuse Windows Setup to create a file in an arbitrary location. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.867Patch KB5000802 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1440Patch KB5000808 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.1817Patch KB5000822 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17134.2087Patch KB5000809
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26889?
CVE-2021-26889 is classified as a critical privilege escalation vulnerability.
How can I fix CVE-2021-26889?
To fix CVE-2021-26889, you should apply the latest security updates provided by Microsoft.
What versions of Windows are affected by CVE-2021-26889?
CVE-2021-26889 affects various versions of Windows 10 and Windows Server, specifically version 20H2 and others identified in the advisory.
Can CVE-2021-26889 be exploited remotely?
CVE-2021-26889 requires local access for exploitation, making it less likely to be executed remotely.
What should I do if I cannot apply the patch for CVE-2021-26889 immediately?
If immediate patching is not possible, limit local access to affected systems as a temporary mitigation for CVE-2021-26889.