PT-2022-6124 · Microsoft · Windows Backup Service+1
Filip Dragovic
·
Published
2022-01-10
·
Updated
2024-05-29
·
CVE-2023-21752
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows Backup Service versions prior to the fixed version
Description
The issue is related to errors in privilege management within the Windows Backup Service, allowing an attacker to elevate their privileges to the level of SYSTEM. This can potentially impact the system, enabling malicious activities. There have been public proofs of concept (PoCs) released, demonstrating the ability to delete any file and launch a shell with elevated privileges.
Recommendations
For Windows Backup Service versions prior to the fixed version, consider disabling the vulnerable service until a patch is available to prevent potential exploitation. Restrict access to the Windows Backup Service to minimize the risk of elevation of privilege attacks. Avoid using the service for critical operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows
Windows Backup Service