CVE-2021-34484

HIGH KEV

Windows User Profile Service - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-34484 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 31, 2022.

Description

Windows User Profile Service Elevation of Privilege Vulnerability

Scores

CVSS v3 7.8
EPSS 0.0278
EPSS Percentile 86.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-03-31
VulnCheck KEV 2022-03-28
InTheWild.io 2022-01-19
ENISA EUVD EUVD-2021-21139
Status published
Products (18)
microsoft/windows_10_1507 < 10.0.10240.19022
microsoft/windows_10_1607 < 10.0.14393.4583
microsoft/windows_10_1809 < 10.0.17763.2114
microsoft/windows_10_1909 < 10.0.18363.1734
microsoft/windows_10_2004 < 10.0.19041.1165
microsoft/windows_10_20h2 < 10.0.19042.1165
microsoft/windows_10_21h1 < 10.0.19043.1165
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
... and 8 more
Published Aug 12, 2021
KEV Added Mar 31, 2022
Tracked Since Feb 18, 2026