Windows Privilege Escalation Vuln Puts Admin Passwords At Risk

  /     /     /  
Publicated : 23/11/2024   Category : security


Windows Privilege Escalation Vuln Puts Admin Passwords At Risk


Microsoft has issued a temporary workaround for systems vulnerable to CVE-2021-36934, also known as HiveNightmare and SeriousSAM.



Microsoft has issued a temporary workaround for a privilege escalation vulnerability that could expose administrator passwords to non-admin users.
CVE-2021-36934, also called HiveNightmare and SeriousSAM, appears to have been first detected by security researcher Jonas Lykkegaard, Forbes reports. Lykkegaard
noticed
the Security Account Manager (SAM) file had become read-enabled for all users, meaning an attacker with non-admin privileges could access hashed passwords and elevate privileges.
Lykkegaard and other
security researchers
found the issue affected the Windows 11 preview as well as Windows 10. Microsoft has confirmed the problem affects Windows 10 version 1809 and newer operating systems and has
provided workarounds
for systems affected by the flaw.
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database, the company wrote in its CVE.
An attacker who successfully exploited the flaw could run arbitrary code with system privileges and then install programs; view, change, or delete data; or create new accounts with full user rights. They also have the ability to execute code on a target system to exploit the bug. So far Microsoft has not detected exploits in the wild, though it notes exploitation is more likely.
Microsoft has stated it will update the CVE as its investigation continues.
Read more details
here
.

Last News

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security

▸ Debunking Machine Learning in Security. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Windows Privilege Escalation Vuln Puts Admin Passwords At Risk