LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-36948: Microsoft Windows Update Medic Service Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
CVSS 7.8 · High⚠ Actively exploited (CISA KEV)
7.8
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-36948 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Windows Update Medic Service Elevation of Privilege Vulnerability

CVE-2021-36948 is a privilege escalation vulnerability in the Microsoft Windows Update Medic Service. An attacker who already has some level of access on a Windows system could abuse it to gain higher privileges. For IT and security teams, this matters because privilege escalation is a common step after initial access: it can turn a limited foothold into full control of the host and open the door to further movement or data access. Public detail on the exact weakness is limited; treat the Microsoft advisory as the source of truth for scope and fixes.

How it works

The vulnerability sits in the Windows Update Medic Service, a component involved in Windows update health and remediation. CISA describes it as an unspecified flaw that allows privilege escalation. In practical terms, that means a process or user running with lower privileges can interact with the service in a way that causes it to perform actions at a higher privilege level than intended.

Privilege-escalation bugs in system services typically arise from issues such as improper access checks, insecure impersonation, or mishandled privileged operations. Without a published CWE or technical write-up in the provided facts, defenders should assume a local attacker who can already execute code or influence the service’s inputs could elevate to a more powerful context (for example, SYSTEM-equivalent rights). Exact exploit mechanics are not detailed here; confirm behavior and any prerequisites against the vendor advisory rather than relying on third-party summaries.

Am I affected? How to find it in your systems

The issue affects Microsoft Windows systems that include the Windows Update Medic Service. That service is present on modern Windows client and server builds that participate in Windows Update. Inventory should focus on Windows endpoints and servers rather than non-Windows platforms.

How to remediate

Patching is the primary remediation. CISA’s required action is to apply updates per vendor instructions. Deploy the Microsoft security update that fixes CVE-2021-36948 through your normal Windows Update, WSUS, Intune, or Configuration Manager channels. Prioritize internet-facing or high-value systems and those where users have local admin or where untrusted code may run.

Do not rely on workarounds as a permanent substitute; confirm complete remediation guidance in the Microsoft advisory.

If you can't patch immediately

If you must delay the update, reduce the likelihood and impact of successful escalation until you can patch.

These steps lower risk but do not eliminate it. Schedule the official update as soon as operationally possible.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are frequently used to deepen a breach after initial access. The facts supplied do not document ransomware use specifically for this CVE, but any successful elevation can lead to data access, credential theft, or further compromise. If you suspect exploitation, isolate affected hosts, preserve volatile evidence, rotate credentials that may have been exposed, and follow your incident-response process. As a quick external check, you can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior leaks while you continue internal investigation.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
CVSS base score7.8 (High)
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PublishedAug 12, 2021
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities