Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2021-24084
vulnerability analysis and mitigation

Overview

CVE-2021-24084 is a Windows Mobile Device Management Information Disclosure vulnerability that was initially discovered and reported in October 2020. The vulnerability affects various versions of Windows 10 operating systems and could allow unauthorized file system access and information disclosure (Threatpost, Hacker News).

Technical details

The vulnerability exists in the Windows Mobile Device Management component, specifically under the 'access work or school' settings. The issue involves the 'export your management log files' function, which triggers the Device Management Enrollment Service. The service copies log files to specific directories and packages them into a .CAB file, creating a potential attack vector when files are copied into the Windows Temp folder (Threatpost).

Impact

The vulnerability enables attackers to gain unauthorized file system access and read arbitrary files, even without proper permissions. When exploited under specific conditions, it can lead to local privilege escalation (LPE), allowing non-admin users to access privileged files. The impact is particularly severe when system protection is enabled on the C: Drive and at least one local administrator account is present on the computer (Hacker News).

Exploitability

The vulnerability can be exploited by creating a file shortcut link with a predictable file name that would normally be used in the export process, pointing to a target folder or file that the attacker wants to access. Since the Device Management Enrollment Service runs as Local System, it can read any system file that a regular user cannot access. The exploitation method is similar to the LPE approach used in the HiveNightmare bug (Threatpost).

Mitigation and workarounds

While Microsoft has not released an official patch, a temporary fix has been issued through a micropatch. The micropatch checks for the presence of short-cut links during the .CAB file creation process and prevents the copying of any file that doesn't actually reside in C:\Windows\Temp. This solution has been implemented as a stop-gap measure until an official fix is released (Threatpost).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management