LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2004-0210: Microsoft Windows Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2004-0210 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.

CVE-2004-0210 is a privilege elevation vulnerability in the POSIX subsystem on Microsoft Windows. A logged-on user who can exploit it may gain complete control of the system. For IT and security teams, this matters because local privilege escalation turns an ordinary user session into full administrative access, enabling persistence, further lateral movement, or abuse of system resources. Confirm all product and version details against the vendor advisory before acting.

How it works

The weakness is classified as CWE-120, a classic buffer overflow. In this class of flaw, input is copied into a fixed-size buffer without adequate bounds checking. When the POSIX subsystem mishandles such input, memory corruption can occur. An attacker who is already logged on can abuse the condition to elevate privileges from a standard user context to full system control. Public detail on exact trigger mechanics is limited; treat the CISA summary as the authoritative description and verify exploitation prerequisites in the vendor advisory rather than assuming specific call sequences or payloads.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the POSIX subsystem. This subsystem historically provided POSIX-compatible interfaces and may be present on older or specialized Windows installations, though it is not enabled or installed by default in every configuration.

Because exact version ranges are not supplied here, treat any Windows system with the POSIX subsystem as potentially in scope until you confirm against the official advisory.

How to remediate

Patch first. Apply the updates Microsoft released for this issue exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions.

Do not rely on version numbers or KB article IDs not present in the facts; obtain them directly from the vendor.

If you can't patch immediately

Reduce exposure until the update can be applied.

These steps only lower risk; they do not replace the vendor update.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities can lead to full system compromise and subsequent data exposure. Known ransomware use of this CVE is not documented in the provided facts. If you suspect compromise, isolate the host, preserve forensic evidence, and follow your incident-response process. As a further check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-120
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities