cbcvebase.
CVE-2021-41379
published 2021-11-10

CVE-2021-41379: Windows Installer Elevation of Privilege Vulnerability

PriorityP186high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
20.10%
97.2th percentile
Windows Installer Elevation of Privilege Vulnerability

Affected

53 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.1911910.0.10240.19119
microsoftwindows_10_1607< 10.0.14393.477010.0.14393.4770
microsoftwindows_10_1809< 10.0.17763.230010.0.17763.2300
microsoftwindows_10_1909< 10.0.18363.191610.0.18363.1916
microsoftwindows_10_2004< 10.0.19041.134810.0.19041.1348
microsoftwindows_10_20h2< 10.0.19042.134810.0.19042.1348
microsoftwindows_10_21h1< 10.0.19043.134810.0.19043.1348
microsoftwindows_10_version_1507>= 10.0.0 < 10.0.10240.1911910.0.10240.19119
microsoftwindows_10_version_1607>= 10.0.0 < 10.0.14393.477010.0.14393.4770
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.230010.0.17763.2300
microsoftwindows_10_version_1909>= 10.0.0 < 10.0.18363.191610.0.18363.1916
microsoftwindows_10_version_2004>= 10.0.0 < 10.0.19041.134810.0.19041.1348
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.134810.0.19042.1348
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.134810.0.19043.1348
microsoftwindows_11_21h2< 10.0.22000.31810.0.22000.318
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.31810.0.22000.318
microsoftwindows_7>= 6.1.0 < 6.1.7601.257696.1.7601.25769
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.257696.1.7601.25769
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.201746.3.9600.20174
microsoftwindows_server_2004< 10.0.19041.134810.0.19041.1348
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.0.0 < 6.1.7601.257696.1.7601.25769
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.0 < 6.1.7601.257696.1.7601.25769
microsoftwindows_server_2008_service_pack_2>= 6.0.0 < 6.0.6003.212826.0.6003.21282
microsoftwindows_server_2012

Detection & IOCsextracted from sources · hover to see the quote

snort
SID 58635
snort
SID 58636
  • The exploit leverages the DACL for Microsoft Edge Elevation Service to replace any executable file on the system with an MSI file, enabling code execution as administrator. Monitor for unexpected MSI file writes over arbitrary executables, especially via the Edge Elevation Service.
  • Talos detected malware samples in the wild actively exploiting CVE-2021-41379; hunt for anomalous privilege escalation activity on all Windows versions including fully patched Windows 11 and Server 2022.
  • A public proof-of-concept exploit was published on GitHub on Nov. 22, 2021 by researcher Abdelhamid Naceri; the PoC bypasses the November patch. Treat any Windows Installer privilege escalation attempts post-Nov. 22 as potentially using this bypass.
  • ·The original November 9 patch for CVE-2021-41379 was incomplete and bypassable; the actual remediation requires the December 2021 patch for CVE-2021-43883.
  • ·At the time of the Talos blog publication, no patch from Microsoft was available for the bypass variant; Snort rules 58635/58636 were the primary mitigation.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vulncheck5.5MEDIUM
cisa7.8HIGH
vendor_msrc5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.