CVE-2021-41379
published 2021-11-10CVE-2021-41379: Windows Installer Elevation of Privilege Vulnerability
PriorityP186high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
20.10%
97.2th percentile
Windows Installer Elevation of Privilege Vulnerability
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19119 | 10.0.10240.19119 |
| microsoft | windows_10_1607 | < 10.0.14393.4770 | 10.0.14393.4770 |
| microsoft | windows_10_1809 | < 10.0.17763.2300 | 10.0.17763.2300 |
| microsoft | windows_10_1909 | < 10.0.18363.1916 | 10.0.18363.1916 |
| microsoft | windows_10_2004 | < 10.0.19041.1348 | 10.0.19041.1348 |
| microsoft | windows_10_20h2 | < 10.0.19042.1348 | 10.0.19042.1348 |
| microsoft | windows_10_21h1 | < 10.0.19043.1348 | 10.0.19043.1348 |
| microsoft | windows_10_version_1507 | >= 10.0.0 < 10.0.10240.19119 | 10.0.10240.19119 |
| microsoft | windows_10_version_1607 | >= 10.0.0 < 10.0.14393.4770 | 10.0.14393.4770 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2300 | 10.0.17763.2300 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.1916 | 10.0.18363.1916 |
| microsoft | windows_10_version_2004 | >= 10.0.0 < 10.0.19041.1348 | 10.0.19041.1348 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1348 | 10.0.19042.1348 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1348 | 10.0.19043.1348 |
| microsoft | windows_11_21h2 | < 10.0.22000.318 | 10.0.22000.318 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.318 | 10.0.22000.318 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25769 | 6.1.7601.25769 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25769 | 6.1.7601.25769 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20174 | 6.3.9600.20174 |
| microsoft | windows_server_2004 | < 10.0.19041.1348 | 10.0.19041.1348 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < 6.1.7601.25769 | 6.1.7601.25769 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < 6.1.7601.25769 | 6.1.7601.25769 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < 6.0.6003.21282 | 6.0.6003.21282 |
| microsoft | windows_server_2012 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
SID 58635
snort↗
SID 58636
- →The exploit leverages the DACL for Microsoft Edge Elevation Service to replace any executable file on the system with an MSI file, enabling code execution as administrator. Monitor for unexpected MSI file writes over arbitrary executables, especially via the Edge Elevation Service. ↗
- →Talos detected malware samples in the wild actively exploiting CVE-2021-41379; hunt for anomalous privilege escalation activity on all Windows versions including fully patched Windows 11 and Server 2022. ↗
- →A public proof-of-concept exploit was published on GitHub on Nov. 22, 2021 by researcher Abdelhamid Naceri; the PoC bypasses the November patch. Treat any Windows Installer privilege escalation attempts post-Nov. 22 as potentially using this bypass. ↗
- ·The original November 9 patch for CVE-2021-41379 was incomplete and bypassable; the actual remediation requires the December 2021 patch for CVE-2021-43883. ↗
- ·At the time of the Talos blog publication, no patch from Microsoft was available for the bypass variant; Snort rules 58635/58636 were the primary mitigation. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vulncheck5.5MEDIUM
cisa7.8HIGH
vendor_msrc5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hxf7-qh53-96j5: Windows Installer Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-41379 [HIGH] CWE-269 GHSA-hxf7-qh53-96j5: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
VulnCheck
Microsoft Windows Installer Privilege Escalation Vulnerability
vulncheck·2021·CVSS 5.5
CVE-2021-41379 [MEDIUM] CWE-1386 Microsoft Windows Installer Privilege Escalation Vulnerability
Microsoft Windows Installer Privilege Escalation Vulnerability
Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.rapid7.com/blog/post/2021/11/30/ongoing-exploitation-of-windows-installer-cve-2021-41379/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.acronis.com/en/tru/posts/makop-ransomware-guloader-and-privilege-escalation-in-attacks-against-indian-businesses/; https://securelist.com/global-report-security-services-2026/119233/
Exploit PoC: https://vulncheck.com/xdb/7fc0e1d60191
Remediation Due: 2022-03-17
CISA
Microsoft Windows Installer Privilege Escalation Vulnerability
cisa·2022-03-03·CVSS 7.8
CVE-2021-41379 [HIGH] CWE-1386 Microsoft Windows Installer Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows Installer Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-41379
Remediation Due Date: 2022-03-17
Microsoft
Windows Installer Elevation of Privilege Vulnerability
vendor_msrc·2021-11-09·CVSS 5.5
CVE-2021-41379 [MEDIUM] Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker would only be able to delete targeted files on a system. They would not gain privileges to view or modify file contents.
Windows Installer: Windows Installer
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5007206
Reference: https://support.microsoft.com/help/5007206
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5007189
Reference: https://supp
No public exploits indexed.
Krebs
Microsoft Patch Tuesday, December 2021 Edition
blogs_krebs·2021-12-14
Microsoft Patch Tuesday, December 2021 Edition
Microsoft, Adobe, and Google all issued security updates to their products today. The Microsoft patches include six previously disclosed security flaws, and one that is already being actively exploited. But this month’s Patch Tuesday is overshadowed by the “Log4Shell” 0-day exploit in a popular Java library that web server administrators are now racing to find and patch amid widespread exploitation of the flaw.
Log4Shell is the name picked for a critical flaw disclosed Dec. 9 in the popular logging library for Java called “log4j,” which is included in a huge number of Java applications. Publicly released exploit code allows an attacker to force a server running a vulnerable log4j library to execute commands, such as downloading malicious software or opening a backdoor connection to the se
Krebs
Microsoft Patch Tuesday, December 2021 Edition
blogs_krebs·2021-12-14
Microsoft Patch Tuesday, December 2021 Edition
Microsoft , Adobe , and Google all issued security updates to their products today. The Microsoft patches include six previously disclosed security flaws, and one that is already being actively exploited. But this month’s Patch Tuesday is overshadowed by the “ Log4Shell ” 0-day exploit in a popular Java library that web server administrators are now racing to find and patch amid widespread exploitation of the flaw.
Log4Shell is the name picked for a critical flaw disclosed Dec. 9 in the popular logging library for Java called “ log4j ,” which is included in a huge number of Java applications. Publicly released exploit code allows an attacker to force a server running a vulnerable log4j library to execute commands, such as downloading malicious software or opening a backdoor connection to
Tenable
Microsoft’s December 2021 Patch Tuesday Addresses 67 CVEs (CVE-2021-43890)
blogs_tenable·2021-12-14·CVSS 7.1
[HIGH] Microsoft’s December 2021 Patch Tuesday Addresses 67 CVEs (CVE-2021-43890)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Threat Source Newsletter (Dec. 2, 2021)
blogs_talos·2021-12-02
Threat Source Newsletter (Dec. 2, 2021)
Good afternoon, Talos readers.
The Thanksgiving holiday in the U.S. didn't slow us down at all, even though we were all still trying to sleep off the food coma from the long weekend. But we came back this week with lots of fun content.
Cisco received an early Christmas present when we were named a leader in incident response services by a recent IDC MarketScape report. We are incredibly proud of this honor, and you can find out what sets our incident response services apart by reading the blog here.
We're also excited because Cisco Talos Incident Response recently grew with the addition of the CTIR Red Team, which can perform penetration tests (even physical pen tests where they try to access an organization's physical office). Our new case study shows how this team discovered a vulnera
Talos
Threat Source Newsletter (Dec. 2, 2021)
blogs_talos·2021-12-02
Threat Source Newsletter (Dec. 2, 2021)
## Threat Source Newsletter (Dec. 2, 2021)
Good afternoon, Talos readers.
The Thanksgiving holiday in the U.S. didn't slow us down at all, even though we were all still trying to sleep off the food coma from the long weekend. But we came back this week with lots of fun content.
Cisco received an early Christmas present when we were named a leader in incident response services by a recent IDC MarketScape report. We are incredibly proud of this honor, and you can find out what sets our incident response services apart by reading the blog here .
We're also excited because Cisco Talos Incident Response recently grew with the addition of the CTIR Red Team, which can perform penetration tests (even physical pen tests where they try to access an organization's physical office). Our new case s
Checkpoint
29th November – Threat Intelligence Report
blogs_checkpoint·2021-11-29·CVSS 7.5
CVE-2021-40444 [HIGH] 29th November – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 29th November – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
GoDaddy has announced they suffered a data breach with data of up to 1.2 million of its customers being exposed after an unauthorized person used a compromised password to gain access to the company’s Managed WordPress hosting environment.
Iranian airline Mahan Air has been victim of a cyber-attack which resulted in it
Talos
Attackers exploiting zero-day vulnerability in Windows Installer — Here’s what you need to know and Talos’ coverage
blogs_talos·2021-11-23·CVSS 5.5
[MEDIUM] Attackers exploiting zero-day vulnerability in Windows Installer — Here’s what you need to know and Talos’ coverage
## Attackers exploiting zero-day vulnerability in Windows Installer — Here’s what you need to know and Talos’ coverage
Cisco Talos is releasing new SNORTⓇ rules to protect against the exploitation of a zero-day elevation of privilege vulnerability in Microsoft Windows Installer. This vulnerability allows an attacker with a limited user account to elevate their privileges to become an administrator. This vulnerability affects every version of Microsoft Windows, including fully patched Windows 11 and Server 2022. Talos has already detected malware samples in the wild that are attempting to take advantage of this vulnerability.
Microsoft released an update that was intended to fix CVE-2021-41379 on Nov. 9 as part of its monthly security update . Security researcher Abdelhamid Naceri initial
Talos
Attackers exploiting zero-day vulnerability in Windows Installer — Here’s what you need to know and Talos’ coverage
blogs_talos·2021-11-23·CVSS 5.5
[MEDIUM] Attackers exploiting zero-day vulnerability in Windows Installer — Here’s what you need to know and Talos’ coverage
Cisco Talos is releasing new SNORTⓇ rules to protect against the exploitation of a zero-day elevation of privilege vulnerability in Microsoft Windows Installer. This vulnerability allows an attacker with a limited user account to elevate their privileges to become an administrator. This vulnerability affects every version of Microsoft Windows, including fully patched Windows 11 and Server 2022. Talos has already detected malware samples in the wild that are attempting to take advantage of this vulnerability.
Microsoft released an update that was intended to fix CVE-2021-41379 on Nov. 9 as part of its monthly security update. Security researcher Abdelhamid Naceri initially discovered this elevation of privilege vulnerability and worked with Microsoft to address it. However, the patch relea
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41379https://www.zerodayinitiative.com/advisories/ZDI-21-1308/https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41379https://www.zerodayinitiative.com/advisories/ZDI-21-1308/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-41379
2021-11-10
Published
2022-03-03
Added to CISA KEV
Exploited in the wild