CVE-2021-36934
vulnerability analysis and mitigation

Overview

CVE-2021-36934, also known as 'HiveNightmare' or 'SeriousSAM', is a critical elevation of privilege vulnerability discovered in July 2021. The vulnerability exists due to overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database in Windows 10 and 11 systems. The vulnerability affects Windows 10 version 1809 and later versions (Rapid7 Blog, CERT/CC).

Technical details

The vulnerability stems from the BUILTIN\Users group being granted RX (read and execute) permissions to files in the %windir%\system32\config directory. When a Volume Shadow Copy Service (VSS) shadow copy of the system drive is available, non-privileged users can access sensitive security-related files. The vulnerability has received a CVSS v3.1 base score of 7.8 (HIGH), with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

The exploitation of this vulnerability allows attackers to extract and leverage account password hashes, discover the original Windows installation password, obtain DPAPI computer keys for decrypting all computer private keys, and acquire computer machine accounts for potential silver ticket attacks. An attacker who successfully exploits this vulnerability can run arbitrary code with SYSTEM privileges, install programs, view, change, or delete data, and create new accounts with full user rights (CERT/CC, NVD).

Exploitability

A public proof-of-concept exploit is available that allows non-admin users to retrieve all registry hives. Security researcher Kevin Beaumont demonstrated that CVE-2021-36934 can be used to obtain local hashes and pass them to a remote machine, achieving remote code execution as SYSTEM on arbitrary targets. An attacker must have the ability to execute code on a victim system to exploit this vulnerability (Rapid7 Blog).

Mitigation and workarounds

Microsoft released a patch on August 10, 2021, to address the vulnerability. However, installing the security update alone is not sufficient for complete mitigation. Users must also manually delete all shadow copies of system files, including the SAM database, after installing the patch. The deletion of shadow copies can be accomplished using the command 'vssadmin delete shadows /for=%systemdrive% /Quiet'. Additionally, access to the contents of %windir%\system32\config should be restricted using the command 'icacls %windir%\system32\config*.* /inheritance:e' (Rapid7 Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management