PT-2021-3680 · Microsoft · Windows 10+1

·

CVE-2021-36934

·

Published

2021-07-20

·

Updated

2026-08-10

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions 10 v1809 and later
Description An elevation of privilege issue exists due to overly permissive Access Control Lists (ACLs) on multiple system files located in the %windir%system32config directory, specifically the Security Accounts Manager (SAM), SYSTEM, and SECURITY registry hive files. A local attacker with the ability to execute code on the system can access these files through Volume Shadow Copies to extract hashed passwords, DPAPI encryption keys, and computer account details used for Active Directory joins. This allows the attacker to crack hashes offline and subsequently run arbitrary code with SYSTEM privileges, enabling them to install programs, modify data, or create new accounts with full administrative rights.
Recommendations For Microsoft Windows versions 10 v1809 and later, install the provided security update and manually delete all volume shadow copies of system files, including the SAM database. Restrict access to the contents of the %windir%system32config directory to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03913
CVE-2021-36934

Affected Products

Windows
Windows 10