CVE-2021-34484
vulnerability analysis and mitigation

Overview

CVE-2021-34484 is a Windows User Profile Service Elevation of Privilege vulnerability that affects all Microsoft Windows operating system versions, including Windows 11 and Server 2022. Initially discovered and disclosed in August 2021, this vulnerability was first considered a low-priority arbitrary directory-deletion issue by Microsoft (Rapid7, SecMaster).

Technical details

The vulnerability resides in the User Profile Service, specifically in the code responsible for creating temporary user profile folders when the original profile folder is damaged or locked. The issue involves the process of copying folders and files from the user's original profile folder to the temporary one, which runs with Local System privileges. An attacker can exploit this by creating symbolic links in the temporary user profile folder (C:\Users\TEMP), causing the service to create folders in unauthorized system locations (SecMaster).

Impact

When successfully exploited, this vulnerability allows an attacker to elevate privileges to SYSTEM level on the target machine. This could potentially enable an attacker to gain complete control over the affected system, though local access is required for exploitation (SecMaster).

Mitigation and workarounds

Microsoft has released security patches as part of its August 2021 updates. However, due to the discovery of patch bypasses, additional fixes were required. Third-party security firm Opatch has released an unofficial micropatch to address the vulnerability while waiting for official fixes from Microsoft. The patch is available for various Windows 10 versions (v21H1, v20H2, v2004, v1909) and Windows Server 2019 (SecMaster).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management