LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-36934: Microsoft Windows SAM Local Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 10, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-36934 to its Known Exploited Vulnerabilities catalog on Feb 10, 2022, with a federal patch deadline of Feb 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.

CVE-2021-36934 is a local privilege escalation vulnerability in Microsoft Windows. When a Volume Shadow Copy (VSS) of the system drive exists, ordinary users can read the Security Account Manager (SAM) database file. That access can let any local user raise their privileges to SYSTEM. The issue matters because SYSTEM-level access gives full control of the host, enabling further lateral movement, persistence, or data theft inside an environment. Confirm exact scope and fixed builds against the Microsoft vendor advisory.

How it works

The weakness is classified as CWE-1220 (insufficient granularity of access control). Windows stores account password hashes and related security data in the SAM. Under normal conditions those files are locked and readable only by highly privileged processes. When a VSS shadow copy of the system volume is present, the ACLs on the shadow-copy versions of the SAM (and related registry hives) can be overly permissive. A low-privileged local user can therefore open and read the shadow-copy SAM. With the extracted credential material the attacker can then impersonate or create SYSTEM-level tokens. No remote exploit path is described in the provided facts; the attack requires local code execution or an interactive logon on the affected machine. Exact file paths, tools, or exploitation sequences must be verified against the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems on which Volume Shadow Copies of the system drive have been created. Typical locations include workstations, member servers, and domain controllers that have System Restore, backup software, or manual VSS snapshots enabled. Inventory steps:

How to remediate

Patch first. Apply the security updates Microsoft released for CVE-2021-36934 exactly as directed in the vendor advisory and in the CISA required action (“Apply updates per vendor instructions”). After patching:

If you can't patch immediately

Implement compensating controls until the vendor update can be deployed:

If your data may have been exposed

Actively exploited local privilege-escalation flaws can be a stepping stone to broader compromise and data theft, even when ransomware use has not been documented for this CVE. If you suspect the vulnerability was abused, isolate the host, preserve forensic images, rotate credentials that may have been extracted from the SAM, and review authentication logs for follow-on activity. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether associated accounts appear in prior third-party breaches while you complete incident response.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-1220
Added to CISA KEVFeb 10, 2022
Federal patch deadlineFeb 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities