Description
Windows Mobile Device Management Information Disclosure Vulnerability
In plain language
AI Act nowCVE-2021-24084 is a Windows bug where a low-privileged user on the same computer can read confidential mobile device management data; if you have untrusted users/accounts on your Windows devices, you should act now to install the fixed Windows builds.
CVE-2021-24084 is a local information disclosure (CWE-59) in Windows Mobile Device Management where a low-privileged local user can read confidential data stored on the machine related to managed mobile devices.
What to do now
- Identify your exact Windows version/build on each affected machine (Windows 10 and Windows Server variants) and compare it to the fixed builds below.
- If your machine is Windows 10 or Windows Server and the build is older than the fixed build for your branch, plan an immediate update to reach the fixed versions listed.
- Prioritize machines where multiple user accounts exist (including helpdesk/operations), and where any account could be obtained by an attacker (for example, through phishing or credential reuse).
- After updating, re-check the installed Windows build number to confirm it matches one of the “fixed in” versions for your branch.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-24084 and every CVE in our database. Create a free account — no credit card required.
Create Free Account