CVE-2021-36961: Microsoft Windows Installer Service Directory Junction Denial-of-Service Vulnerability
Windows Installer Denial of Service Vulnerability
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Windows Installer Service. By creating a directory junction, an attacker can abuse the service to create a directory. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23462Patch KB5005607 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20120Patch KB5005627 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21218Patch KB5005618 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.25712Patch KB5005615 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4651Patch KB5005573 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20120Patch KB5005613 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19060Patch KB5005569 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1237Patch KB5005565 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1237Patch KB5005565 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1801Patch KB5005566 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2183Patch KB5005568 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1237Patch KB5005565 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.230Patch KB5005575
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36961?
CVE-2021-36961 is classified as a denial-of-service vulnerability that can significantly disrupt the operation of affected systems.
How do I fix CVE-2021-36961?
To fix CVE-2021-36961, apply the relevant patches provided by Microsoft for your version of Windows.
Which versions of Windows are affected by CVE-2021-36961?
CVE-2021-36961 affects multiple versions of Windows including Windows 10, Windows Server 2008 R2, and Windows Server 2019 among others.
What types of attacks can exploit CVE-2021-36961?
CVE-2021-36961 can be exploited by local attackers to cause a denial-of-service condition on affected installations.
Is there a workaround for CVE-2021-36961?
Currently, the best approach for CVE-2021-36961 is to ensure that your system is updated with the latest security patches from Microsoft.