PT-2021-3680 · Microsoft · Windows 10+1
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions 10 v1809 and later
Description
An elevation of privilege issue exists due to overly permissive Access Control Lists (ACLs) on multiple system files located in the
%windir%system32config directory, specifically the Security Accounts Manager (SAM), SYSTEM, and SECURITY registry hive files. A local attacker with the ability to execute code on the system can access these files through Volume Shadow Copies to extract hashed passwords, DPAPI encryption keys, and computer account details used for Active Directory joins. This allows the attacker to crack hashes offline and subsequently run arbitrary code with SYSTEM privileges, enabling them to install programs, modify data, or create new accounts with full administrative rights.Recommendations
For Microsoft Windows versions 10 v1809 and later, install the provided security update and manually delete all volume shadow copies of system files, including the SAM database.
Restrict access to the contents of the
%windir%system32config directory to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 10