Windows Elevation of Privilege Vulnerability
Summary
| CVE | CVE-2021-36934 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-22 07:15:11 UTC |
| Updated | 2026-08-10 20:19:00 UTC |
| Description | An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have the ability to execute code on a victim system to exploit this vulnerability. After installing this security update, you must manually delete all shadow copies of system files, including the SAM database, to fully mitigate this vulnerabilty. Simply installing this security update will not fully mitigate this vulnerability. See KB5005357- Delete Volume Shadow Copies. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.672520000 probability, percentile 0.992440000 (date 2026-08-27)
CISA KEV: Listed on 2022-02-10; due 2022-02-24; ransomware use Unknown
Problem Types: NVD-CWE-Other | Elevation of Privilege | CWE-noinfo Not enough information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:T/RC:C |
| 2.0 | [email protected] | Primary | 4.6 | AV:L/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
CISA Known Exploited Vulnerability
| Vendor | Microsoft |
|---|---|
| Product | Windows |
| Name | Microsoft Windows SAM Local Privilege Escalation Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2021-36934 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows 10 1809 | All | All | All | All |
| Operating System | Microsoft | Windows 10 1909 | All | All | All | All |
| Operating System | Microsoft | Windows 10 2004 | All | All | All | All |
| Operating System | Microsoft | Windows 10 20h2 | All | All | All | All |
| Operating System | Microsoft | Windows 10 21h1 | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Microsoft | Windows 10 Version 1809 | affected 10.0.17763.0 10.0.17763.2114 custom | 32-bit Systems, x64-based Systems |
| CNA | Microsoft | Windows 10 Version 1809 | affected 10.0.0 10.0.17763.2114 custom | ARM64-based Systems |
| CNA | Microsoft | Windows 10 Version 1909 | affected 10.0.0 10.0.18363.1734 custom | 32-bit Systems, ARM64-based Systems, x64-based Systems |
| CNA | Microsoft | Windows 10 Version 2004 | affected 10.0.0 10.0.19041.1165 custom | 32-bit Systems, ARM64-based Systems, x64-based Systems |
| CNA | Microsoft | Windows 10 Version 20H2 | affected 10.0.0 10.0.19042.1165 custom | 32-bit Systems, ARM64-based Systems |
| CNA | Microsoft | Windows 10 Version 21H1 | affected 10.0.0 10.0.19043.1165 custom | 32-bit Systems, ARM64-based Systems, x64-based Systems |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| HiveNightmare AKA SeriousSAM ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| www.kb.cert.org/vuls/id/506989 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory |
| Security Update Guide - Microsoft Security Response Center | af854a3a-2127-422b-91ae-364da2661108 | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36934 | [email protected] | msrc.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2022-02-10T00:00:00.000Z | CVE-2021-36934 added to CISA KEV |
Legacy QID Mappings
- 91797 Microsoft Windows Elevation of Privilege Vulnerability (CVE-2021-36934)(Zero-day)(HiveNightmare/SeriousSAM)