CVE-2021-36934
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.
CISA KEV
- Vendor
- Microsoft
- Product
- Windows
- Due date
- 2022-02-24
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://nvd.nist.gov/vuln/detail/CVE-2021-36934
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.