PT-2021-2081 · Microsoft · Windows

Halov

·

Published

2021-02-09

·

Updated

2026-03-10

·

CVE-2021-24084

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Windows versions prior to the fixed version Windows 10 version 1809 and later versions
Description: A vulnerability in the Windows Mobile Device Management service is related to the lack of protection for service data. Exploitation of this issue may allow an attacker to gain unauthorized access to protected information. The vulnerability can be exploited using the Local Privilege Escalation (LPE) approach. Research indicates that this vulnerability could allow an attacker to read arbitrary files and affect the system.
Recommendations: For Windows versions prior to the fixed version, apply the necessary patches or fixes as soon as they become available. For Windows 10 version 1809 and later versions, consider applying temporary fixes or workarounds, such as those provided by 0patch, until an official patch from Microsoft is released. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Fix

Link Following

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00932
CVE-2021-24084
ZDI-21-178

Affected Products

Windows