CVE-2021-42277: Microsoft Windows Diagnostics Hub Link Following Privilege Escalation Vulnerability
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Microsoft Diagnostics Hub Standard Collector Service. By creating a symbolic link, an attacker can abuse the service to delete a directory. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.9.13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.7.21 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4770Patch KB5007192 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19119Patch KB5007207 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 27550.00Patch KB5007275 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.9.41 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.11.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.318Patch KB5007215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.350Patch KB5007205 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1916Patch KB5007189 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2300Patch KB5007206
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42277?
CVE-2021-42277 has a CVSS score indicating a high severity level due to the potential for local privilege escalation.
What systems are affected by CVE-2021-42277?
CVE-2021-42277 affects various versions of Microsoft Windows and Visual Studio, including Windows 10, Windows Server 2019 and 2022, and Visual Studio 2019.
How do I fix CVE-2021-42277?
To address CVE-2021-42277, users should apply the latest security updates released by Microsoft for the affected products.
What type of vulnerability is CVE-2021-42277?
CVE-2021-42277 is classified as an elevation of privilege vulnerability that allows local attackers to gain higher access rights.
Is CVE-2021-42277 being actively exploited?
There is no public indication that CVE-2021-42277 is being actively exploited, but it is recommended to patch systems to mitigate any potential risk.