Windows 10: Vulnerability CVE-2021-36934

Discus and support Vulnerability CVE-2021-36934 in Windows 10 BSOD Crashes and Debugging to solve the problem; I saw in the press that an additional vulnerability of Windows 10, known as CVE-2021-36934, can be remedied at list until a Microsoft patch is... Discussion in 'Windows 10 BSOD Crashes and Debugging' started by rosv_297, Jul 22, 2021.

  1. rosv_297 Win User

    Vulnerability CVE-2021-36934


    I saw in the press that an additional vulnerability of Windows 10, known as CVE-2021-36934, can be remedied at list until a Microsoft patch is available by running as administrator Win 10 Powershell and then typing: icacls $env:windir\system32\config\*.* /inheritance:efollowed by: vssadmin list shadowsand, if shadows are listed, vssadmin delete shadows /for=C1/QuietI tried to do that but I got the feedback that ‘vssadmin’ is not recognized by the system.Was the print in the press faulty? Thanks for helping!

    :)
     
    rosv_297, Jul 22, 2021
    #1
  2. Brink Win User

    CVE-2021-36934 Windows Elevation of Privilege Vulnerability

    Executive Summary

    An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

    An attacker must have the ability to execute code on a victim system to exploit this vulnerability.

    We will update this CVE with mitigations and workarounds as our investigation progresses.

    FAQ

    No versions of Windows are listed in the Security Updates table. Are all versions vulnerable?

    So far, we can confirm that this issue affects Windows 10 version 1809 and newer client operating systems. We will update this CVE as we continue our investigation. If you wish to be notified when updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this CVE. See Microsoft Technical Security Notifications.



    Read more: https://msrc.microsoft.com/update-gu...CVE-2021-36934
     
    Brink, Jul 22, 2021
    #2
  3. Brink Win User
    Clarified Guidance CVE-2021-34527 Windows Print Spooler Vulnerability

    Source: https://msrc-blog.microsoft.com/2021...vulnerability/
     
    Brink, Jul 22, 2021
    #3
  4. Brink Win User

    Vulnerability CVE-2021-36934

    Updates - TCP/IP:  CVE-2021-24074, CVE-2021-24094, and CVE-2021-24086

    Source:

     
    Brink, Jul 22, 2021
    #4
Thema:

Vulnerability CVE-2021-36934

Loading...
  1. Vulnerability CVE-2021-36934 - Similar Threads - Vulnerability CVE 2021

  2. CVE-2023-38545 cURL vulnerability

    in Windows 10 Gaming
    CVE-2023-38545 cURL vulnerability: Hello!I have a lot of workstations affected by this that are being classified as vulnerable by Tenable. All of these have cURL onboard pre-installed on the machines. I see this means we have to wait for Microsoft to release an update. Can someone please provide any idea as to...
  3. CVE-2023-38545 cURL vulnerability

    in Windows 10 Software and Apps
    CVE-2023-38545 cURL vulnerability: Hello!I have a lot of workstations affected by this that are being classified as vulnerable by Tenable. All of these have cURL onboard pre-installed on the machines. I see this means we have to wait for Microsoft to release an update. Can someone please provide any idea as to...
  4. Is Visual Studio affected by Apache Log4j Vulnerability, CVE-2021-44228?

    in AntiVirus, Firewalls and System Security
    Is Visual Studio affected by Apache Log4j Vulnerability, CVE-2021-44228?: Is Visual Studio Affected by the vulnerability below, and if so what the recommendation is to address it? I mean not only newest version, but for example 2010, 2012, 2013....
  5. CVE-2021-41379

    in Windows 10 Gaming
    CVE-2021-41379: CVE-2021-41379 vulnerability can be hacked if an unupdated computer has any internet access https://answers.microsoft.com/en-us/windows/forum/all/cve-2021-41379/ee8db398-6e99-4061-a3a0-c2dcfea656f7
  6. CVE-2021-41379

    in Windows 10 Software and Apps
    CVE-2021-41379: CVE-2021-41379 vulnerability can be hacked if an unupdated computer has any internet access https://answers.microsoft.com/en-us/windows/forum/all/cve-2021-41379/ee8db398-6e99-4061-a3a0-c2dcfea656f7
  7. Windows – CVE-2021-36934 Work around

    in AntiVirus, Firewalls and System Security
    Windows – CVE-2021-36934 Work around: Hi Everyone,I hope someone can help me.I am currently working in a Windows environment with an Active Directory server managing several servers and workstations I am looking at implementing the work around for CVE-2021-36934 HiveNightmareWhat I am unsure about is how...
  8. Windows Print Spooler Remote Code Execution Vulnerability CVE-2021-34527

    in AntiVirus, Firewalls and System Security
    Windows Print Spooler Remote Code Execution Vulnerability CVE-2021-34527: Do I need to do do/patch something for Windows 10? what? how?Or will this be updated through the standard windows/security updates that install automatically...
  9. Updates - TCP/IP:  CVE-2021-24074, CVE-2021-24094, and CVE-2021-24086

    in Windows 10 News
    Updates - TCP/IP:  CVE-2021-24074, CVE-2021-24094, and CVE-2021-24086: Today Microsoft released a set of fixes affecting Windows TCP/IP implementation that include two Critical Remote Code Execution (RCE) vulnerabilities (CVE-2021-24074, CVE-2021-24094) and an Important Denial of Service (DoS) vulnerability (CVE-2021-24086). The two RCE...
  10. SQLITE vulnerability CVE-2018-20346, CVE-2018-20505, CVE-2018-20506

    in AntiVirus, Firewalls and System Security
    SQLITE vulnerability CVE-2018-20346, CVE-2018-20505, CVE-2018-20506: There is a reported vulnerability in older versions of SQLITE: See 21th Dec 2018 CVE ID has been assigned as CVE-2018-20346, CVE-2018-20505, CVE-2018-20506 https://blade.tencent.com/magellan/index_en.html and https://worthdoingbadly.com/sqlitebug/ However, I see that the...