cbcvebase.
CVE-2021-34484
published 2021-08-12

CVE-2021-34484: Windows User Profile Service Elevation of Privilege Vulnerability

PriorityP182high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-04-21
Exploited in the wild
EPSS
14.39%
96.2th percentile
Windows User Profile Service Elevation of Privilege Vulnerability

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.1902210.0.10240.19022
microsoftwindows_10_1607< 10.0.14393.458310.0.14393.4583
microsoftwindows_10_1809< 10.0.17763.211410.0.17763.2114
microsoftwindows_10_1909< 10.0.18363.173410.0.18363.1734
microsoftwindows_10_2004< 10.0.19041.116510.0.19041.1165
microsoftwindows_10_20h2< 10.0.19042.116510.0.19042.1165
microsoftwindows_10_21h1< 10.0.19043.116510.0.19043.1165
microsoftwindows_10_version_1507>= 10.0.0 < 10.0.10240.1902210.0.10240.19022
microsoftwindows_10_version_1607>= 10.0.0 < 10.0.14393.458310.0.14393.4583
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.211410.0.17763.2114
microsoftwindows_10_version_1909>= 10.0.0 < 10.0.18363.173410.0.18363.1734
microsoftwindows_10_version_2004>= 10.0.0 < 10.0.19041.116510.0.19041.1165
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.116510.0.19042.1165
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.116510.0.19043.1165
microsoftwindows_7>= 6.1.0 < 6.1.7601.256856.1.7601.25685
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.256856.1.7601.25685
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.200946.3.9600.20094
microsoftwindows_server_2004< 10.0.19041.116510.0.19041.1165
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.0.0 < 6.1.7601.256856.1.7601.25685
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.0 < 6.1.7601.256856.1.7601.25685
microsoftwindows_server_2008_service_pack_2>= 6.0.0 < 6.0.6003.211926.0.6003.21192
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.0 < 6.2.9200.234356.2.9200.23435
microsoftwindows_server_2012_r2>= 6.3.0 < 6.3.9600.200946.3.9600.20094

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability resides in the User Profile Service (ProfSrv), specifically in its CreateDirectoryJunction() function, which lacks appropriate checks on directory junction structures. Monitor for suspicious junction creation activity by ProfSrv.
  • Exploitation involves planting a malicious DLL in a system directory and triggering a UAC prompt to cause ProfSrv to load and execute it as NT AUTHORITY\SYSTEM. Monitor for unexpected DLL writes to system directories followed by UAC prompt events.
  • The exploit requires the attacker to supply credentials of a second, non-admin user who has previously logged in at least once. Monitor for unusual cross-user profile access or profile service activity involving secondary user accounts.
  • ·Exploitation requires UAC to be set to the highest level ('Always Notify Me When'). If UAC has been lowered from the default, the SYSTEM-level code execution path via this technique will not work.
  • ·CVE-2021-34484 was patched twice (also as CVE-2022-21919), and both patches were found insufficient. The Metasploit module targets the third iteration tracked as CVE-2022-26904. Ensure the correct patch chain is applied.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.