CVE-2021-34486

HIGH KEV

Windows 10 1809-21H1 and Windows Server 2019-20H2 - Use-After-Free in Event Tracing

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-34486 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 28, 2022. EIP tracks 2 public exploits from researchers including KaLendsi, b1tg.

AI-analyzed exploit summary The repository contains a functional exploit PoC for CVE-2021-34486, targeting a Windows kernel vulnerability in the Event Tracing for Windows (ETW) component. The code demonstrates memory corruption via crafted ETW notifications, leveraging kernel pointer manipulation and arbitrary write primitives.

Description

Windows Event Tracing Elevation of Privilege Vulnerability

Exploits (2)

nomisec WORKING POC 51 stars
by KaLendsi · local
https://github.com/KaLendsi/CVE-2021-34486

The repository contains a functional exploit PoC for CVE-2021-34486, targeting a Windows kernel vulnerability in the Event Tracing for Windows (ETW) component. The code demonstrates memory corruption via crafted ETW notifications, leveraging kernel pointer manipulation and arbitrary write primitives.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Complex
Reliability
Racy
Target: Microsoft Windows (kernel)
No auth needed
Prerequisites: Windows system with vulnerable ETW implementation · Local access to execute the exploit
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by b1tg · poc
https://github.com/b1tg/CVE-2021-34486-exp

This repository contains a functional exploit for CVE-2021-34486, targeting a Windows Event Tracing (ETW) vulnerability. The code demonstrates memory corruption via crafted ETW notifications, likely leading to local privilege escalation (LPE).

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Complex
Reliability
Racy
Target: Microsoft Windows (ETW component)
No auth needed
Prerequisites: Local access to a vulnerable Windows system
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0743
EPSS Percentile 93.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-03-28
VulnCheck KEV 2022-03-28
InTheWild.io 2022-03-28
ENISA EUVD EUVD-2021-21140
CWE
CWE-416
Status published
Products (8)
microsoft/windows_10_1809 < 10.0.17763.2114
microsoft/windows_10_1909 < 10.0.18363.1734
microsoft/windows_10_2004 < 10.0.19041.1165
microsoft/windows_10_20h2 < 10.0.19042.1165
microsoft/windows_10_21h1 < 10.0.19043.1165
microsoft/windows_server_2004 < 10.0.19041.1165
microsoft/windows_server_2019 < 10.0.17763.2114
microsoft/windows_server_20h2 < 10.0.19042.1165
Published Aug 12, 2021
KEV Added Mar 28, 2022
Tracked Since Feb 18, 2026