CVE-2021-42280: Microsoft Windows DiagTrack Service Link Following Privilege Escalation Vulnerability
Windows Feedback Hub Elevation of Privilege Vulnerability
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the DiagTrack service. By creating a symbolic link, an attacker can abuse the service to delete a directory. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4770Patch KB5007192 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.318Patch KB5007215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.350Patch KB5007205 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1916Patch KB5007189 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2300Patch KB5007206
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42280?
CVE-2021-42280 is classified as a critical elevation of privilege vulnerability.
How do I fix CVE-2021-42280?
To fix CVE-2021-42280, apply the latest security updates provided by Microsoft for the affected versions of Windows.
Who is affected by CVE-2021-42280?
CVE-2021-42280 affects various versions of Microsoft Windows, including Windows 10, Windows Server 2019, and Windows 11.
Can CVE-2021-42280 be exploited remotely?
No, CVE-2021-42280 requires local access to the system for exploitation.
What are the potential impacts of CVE-2021-42280?
If exploited, CVE-2021-42280 could allow an attacker to gain elevated privileges on the affected system.