CVE-2021-28326: Microsoft Windows AppX Deployment Service Directory Junction Denial-of-Service Vulnerability
Windows AppX Deployment Server Denial of Service Vulnerability
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the AppX Deployment Service. By creating a directory junction, an attacker can abuse the service to delete the contents of a chosen directory. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
— ZDI
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28326?
CVE-2021-28326 has a severity rating of Critical as it allows local attackers to create a denial-of-service condition.
How do I fix CVE-2021-28326?
To fix CVE-2021-28326, apply the relevant security updates provided by Microsoft for affected Windows versions.
Which systems are affected by CVE-2021-28326?
CVE-2021-28326 affects multiple versions of Windows 10 and Windows Server, specifically the 20H2, 1803, 1809, 1909, and 2004 releases.
Can CVE-2021-28326 be exploited remotely?
CVE-2021-28326 requires local access to exploit, making it not applicable to remote attack scenarios.
How does CVE-2021-28326 affect system availability?
CVE-2021-28326 can be used by attackers to cause a denial-of-service condition, rendering the affected application temporarily unavailable.