PT-2021-3831 · Microsoft · Windows User Profile Service+1

Halov

·

Published

2021-05-05

·

Updated

2023-12-28

·

CVE-2021-26426

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows User Profile Service (ProfSvc) (affected versions not specified)
Description The issue is related to insufficient access restrictions in the implementation of the user account profile picture in the Windows User Profile Service. It allows an attacker to elevate their privileges. There is no information provided about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Link Following

Weakness Enumeration

Related Identifiers

BDU:2021-04161
CVE-2021-26426
ZDI-21-965

Affected Products

Windows
Windows User Profile Service