CVE-2021-36934 — Windows Elevation of Privilege Vulnerability
Executive Summary
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have the ability to execute code on a victim system to exploit this vulnerability. After installing this security update, you must manually delete all shadow copies of system files, including the SAM database, to fully mitigate this vulnerabilty. Simply installing this security update will not fully mitigate this vulnerability. See KB5005357- Delete Volume Shadow Copies.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:T/RC:C
EPSS Score
No EPSS score available for this CVE.
View on FIRST.orgAffected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1809 for 32-bit Systems | 5005030 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5005030 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for ARM64-based Systems | 5005030 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1909 for 32-bit Systems | 5005031 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1909 for x64-based Systems | 5005031 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1909 for ARM64-based Systems | 5005031 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H1 for x64-based Systems | 5005033 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H1 for ARM64-based Systems | 5005033 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H1 for 32-bit Systems | 5005033 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 2004 for 32-bit Systems | 5005033 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 2004 for ARM64-based Systems | 5005033 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 2004 for x64-based Systems | 5005033 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 20H2 for 32-bit Systems | 5005033 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 20H2 for ARM64-based Systems | 5005033 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5005030 |
Security Update | Yes |
5005031 |
Security Update | Yes |
5005033 |
Security Update | Yes |
Exploits & PoC
15 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| HuskyHacks/ShadowSteal | 210 | 2021-07-20 | Pure Nim implementation for exploiting CVE-2021-36934, the SeriousSAM local privilege escalation |
| WiredPulse/Invoke-HiveNightmare | 35 | 2021-07-22 | PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the SAM, Security, and Software Registry hives in Windows 10 version 1809 or newer |
| JoranSlingerland/CVE-2021-36934 | 9 | 2021-07-21 | Fix for the CVE-2021-36934 |
| romarroca/SeriousSam | 9 | 2021-07-22 | HiveNightmare a.k.a. SeriousSam Local Privilege Escalation in Windows – CVE-2021-36934 |
| Wh04m1001/VSSCopy | 8 | 2021-07-22 | Small and dirty PoC for CVE-2021-36934 |
| Sp00kySkelet0n/PyNightmare | 7 | 2021-07-25 | PoC for CVE-2021-36934 Aka HiveNightmare/SeriousSAM written in python3 |
| exploitblizzard/CVE-2021-36934 | 7 | 2021-07-27 | HiveNightmare aka SeriousSAM |
| n3tsurge/CVE-2021-36934 | 5 | 2021-07-21 | Detection and Mitigation script for CVE-2021-36934 (HiveNightmare aka. SeriousSam) |
| Preventions/CVE-2021-36934 | 3 | 2021-07-24 | C# PoC for CVE-2021-36934/HiveNightmare/SeriousSAM |
| chron1k/oxide_hive | 3 | 2021-08-12 | Exploit for CVE-2021-36934 |
| VertigoRay/CVE-2021-36934 | 2 | 2021-07-22 | Windows Elevation of Privilege Vulnerability (SeriousSAM) |
| bytesizedalex/CVE-2021-36934 | 2 | 2021-07-22 | CVE-2021-36934 PowerShell scripts |
| websecnl/CVE-2021-36934 | 2 | 2021-08-01 | SeriousSAM Auto Exploiter |
| grishinpv/poc_CVE-2021-36934 | 2 | 2021-08-02 | POC experiments with Volume Shadow copy Service (VSS) |
| WiredPulse/Invoke-HiveDreams | 1 | 2021-07-22 | A capability to identify and remediate CVE-2021-36934 (HiveNightmare) |
Detection Rules
Detection availableCommunity detection & vulnerability-scanning rules aggregated from Sigma and Nuclei templates. Validate and tune to your environment before deploying.
Sigma rules 2
Acknowledgments
Microsoft has not published researcher acknowledgments for this CVE, or they are not yet reflected in our data source. Check the MSRC advisory directly for the most current credit information.