CVE-2021-36962: Microsoft Windows Installer Service Directory Junction Information Disclosure Vulnerability
Windows Installer Information Disclosure Vulnerability
Other sources
This vulnerability allows local attackers to disclose sensitive information on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Windows Installer Service. By creating a directory junction, an attacker can abuse the service to disclose the contents of arbitrary files. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21218Patch KB5005618 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23462Patch KB5005607 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.25712Patch KB5005615 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20120Patch KB5005613 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20120Patch KB5005627 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4651Patch KB5005573 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1237Patch KB5005565 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19060Patch KB5005569 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1237Patch KB5005565 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1237Patch KB5005565 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1801Patch KB5005566 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2183Patch KB5005568
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36962?
CVE-2021-36962 has a severity rating of important according to Microsoft.
How do I fix CVE-2021-36962?
To fix CVE-2021-36962, you need to apply the latest security updates provided by Microsoft for the affected Windows versions.
Which Microsoft products are affected by CVE-2021-36962?
CVE-2021-36962 affects several versions of Microsoft Windows including Windows 10, Windows Server 2016, and Windows 7.
Can CVE-2021-36962 be exploited remotely?
No, CVE-2021-36962 is a local information disclosure vulnerability that requires local access to the affected systems to exploit.
What type of vulnerability is CVE-2021-36962?
CVE-2021-36962 is classified as an information disclosure vulnerability in the Windows Installer.