cbcvebase.
CVE-2021-26887
published 2021-03-11

CVE-2021-26887: An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited the vulnerability would be able to begin redirecting another user's personal data to a created folder. To exploit the vulnerability, an attacker can create a new folder under the Folder Redirection root path and create a junction on a newly created User folder. When the new user logs in, Folder Redirection would start redirecting to the folder and copying personal data. This elevation of privilege vulnerability can only be addressed by reconfiguring Folder Redirection with Offline files and restricting permissions, and NOT via a security update for affected Windows Servers. See the FAQ section of this CVE for configuration guidance.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1507
microsoftwindows_10_version_1607
microsoftwindows_10_version_1803
microsoftwindows_10_version_1809
microsoftwindows_10_version_1909
microsoftwindows_10_version_2004
microsoftwindows_10_version_20h2
microsoftwindows_7
microsoftwindows_7_service_pack_1
microsoftwindows_8.1
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1
microsoftwindows_server_2008_service_pack_2
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.0 < publicationpublication
microsoftwindows_server_2012_r2
microsoftwindows_server_2016
microsoftwindows_server_2016
microsoftwindows_server_2016