CVE-2021-34484
published 2021-08-12CVE-2021-34484: Windows User Profile Service Elevation of Privilege Vulnerability
PriorityP182high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-04-21
Exploited in the wild
EPSS
14.39%
96.2th percentile
Windows User Profile Service Elevation of Privilege Vulnerability
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19022 | 10.0.10240.19022 |
| microsoft | windows_10_1607 | < 10.0.14393.4583 | 10.0.14393.4583 |
| microsoft | windows_10_1809 | < 10.0.17763.2114 | 10.0.17763.2114 |
| microsoft | windows_10_1909 | < 10.0.18363.1734 | 10.0.18363.1734 |
| microsoft | windows_10_2004 | < 10.0.19041.1165 | 10.0.19041.1165 |
| microsoft | windows_10_20h2 | < 10.0.19042.1165 | 10.0.19042.1165 |
| microsoft | windows_10_21h1 | < 10.0.19043.1165 | 10.0.19043.1165 |
| microsoft | windows_10_version_1507 | >= 10.0.0 < 10.0.10240.19022 | 10.0.10240.19022 |
| microsoft | windows_10_version_1607 | >= 10.0.0 < 10.0.14393.4583 | 10.0.14393.4583 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2114 | 10.0.17763.2114 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.1734 | 10.0.18363.1734 |
| microsoft | windows_10_version_2004 | >= 10.0.0 < 10.0.19041.1165 | 10.0.19041.1165 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1165 | 10.0.19042.1165 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1165 | 10.0.19043.1165 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25685 | 6.1.7601.25685 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25685 | 6.1.7601.25685 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20094 | 6.3.9600.20094 |
| microsoft | windows_server_2004 | < 10.0.19041.1165 | 10.0.19041.1165 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < 6.1.7601.25685 | 6.1.7601.25685 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < 6.1.7601.25685 | 6.1.7601.25685 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < 6.0.6003.21192 | 6.0.6003.21192 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.0 < 6.2.9200.23435 | 6.2.9200.23435 |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < 6.3.9600.20094 | 6.3.9600.20094 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability resides in the User Profile Service (ProfSrv), specifically in its CreateDirectoryJunction() function, which lacks appropriate checks on directory junction structures. Monitor for suspicious junction creation activity by ProfSrv. ↗
- →Exploitation involves planting a malicious DLL in a system directory and triggering a UAC prompt to cause ProfSrv to load and execute it as NT AUTHORITY\SYSTEM. Monitor for unexpected DLL writes to system directories followed by UAC prompt events. ↗
- →The exploit requires the attacker to supply credentials of a second, non-admin user who has previously logged in at least once. Monitor for unusual cross-user profile access or profile service activity involving secondary user accounts. ↗
- ·Exploitation requires UAC to be set to the highest level ('Always Notify Me When'). If UAC has been lowered from the default, the SYSTEM-level code execution path via this technique will not work. ↗
- ·CVE-2021-34484 was patched twice (also as CVE-2022-21919), and both patches were found insufficient. The Metasploit module targets the third iteration tracked as CVE-2022-26904. Ensure the correct patch chain is applied. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mp6h-cxp8-82j6: Windows User Profile Service Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-34484 [HIGH] CWE-269 GHSA-mp6h-cxp8-82j6: Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
VulnCheck
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
vulncheck·2021·CVSS 7.8
CVE-2021-34484 [HIGH] CWE-269 Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Exploitation References: https://twitter.com/billdemirkapi/status/1508527492285575172; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://security.packt.com/how-lapsus-breached-okta-and-why-you-should-test-your-own-capabilities/; https://www.cisa.gov/sites/default/files/2023-08/CSRB_Lapsus%24_508c.pdf
Remediation Due: 2022-04-21
CISA
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
cisa·2022-03-31·CVSS 7.8
CVE-2021-34484 [HIGH] CWE-269 Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-34484
Remediation Due Date: 2022-04-21
Microsoft
Windows User Profile Service Elevation of Privilege Vulnerability
vendor_msrc·2021-08-10·CVSS 7.8
CVE-2021-34484 [HIGH] Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service: Windows User Profile Service
Microsoft: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005030
Reference: https://support.microsoft.com/help/5005030
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005031
Reference: https://support.microsoft.com/help/5005031
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005033
Reference: https://support.microsoft.com/help/5005033
Reference: https://catalog.update.microsoft.com/v7/sit
No detection rules found.
Checkpoint
15th November – Threat Intelligence Report
blogs_checkpoint·2021-11-15
CVE-2021-42237 15th November – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 15th November – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 15th November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research notes a 178% increase in the number of malicious shopping websites, compared to the rest of the year, spotting over 5300 different malicious websites per week ahead of the end of this year’s e-shopping season.
Check Point Research has analyzed the operations of threat actor MosesStaff following its
Checkpoint
1st November – Threat Intelligence Report
blogs_checkpoint·2021-11-01
CVE-2021-34484 1st November – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 1st November – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 1st November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
A cyberattack has disrupted gasoline sale in Iran. Fueling machines showed a message saying “cyberattack 64411”, the number being the phone number for the office of Iran’s Supreme Leader, and a reference to the attack on Iran’s railway system attributed to the Indra attack group.
The North Korean threat group Lazarus (AK
Qualys
Microsoft and Adobe Patch Tuesday (August 2021) – Microsoft 51 Vulnerabilities with 7 Critical, Adobe 29 Vulnerabilities
blogs_qualys·2021-08-10·CVSS 7.0
CVE-2021-36942 [HIGH] Microsoft and Adobe Patch Tuesday (August 2021) – Microsoft 51 Vulnerabilities with 7 Critical, Adobe 29 Vulnerabilities
## Microsoft Patch Tuesday – August 2021
Microsoft patched 51 vulnerabilities in their August 2021 Patch Tuesday release, and 7 of them are rated as critical severity. Three 0-day vulnerability patches were included in the release.
## Critical Microsoft Vulnerabilities Patched
CVE-2021-36942 – Windows LSA Spoofing Vulnerability
An unauthenticated attacker could call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM. A malicious user can use this attack to take complete control over windows domain Per Microsoft, this vulnerability affects all servers, but domain controllers should be prioritized in terms of applying security updates.
CVE-2021-34481 – Windows Print Spooler Remote Code Execution Vulnerability
A remote cod
Crowdstrike
August 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] August 2021 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
August 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] August 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2021-08-12
Published
2022-03-31
Added to CISA KEV
Exploited in the wild