Description
Windows Installer Elevation of Privilege Vulnerability
In plain language
AI Act nowCVE-2021-41379 is a Windows Installer bug that lets a low-privileged local attacker run with higher privileges; small businesses should treat it as urgent because it has been used in ransomware.
CVE-2021-41379 is a local privilege escalation in Windows Installer caused by improper handling of symbolic links, allowing a low-privileged attacker to gain elevated rights without needing user interaction; it is listed in CISA KEV and has been used in ransomware campaigns.
What to do now
- Check which Windows versions you run (Windows 10, Windows 11, Windows 7, Windows 8.1, Windows RT 8.1, and Windows Server variants).
- Confirm whether each system is at or beyond the fixed build for its branch (use your update history or system build number).
- Update Windows Installer via Microsoft’s security update guidance for CVE-2021-41379 until your systems reach the fixed versions listed by Microsoft.
- If you cannot patch right away, restrict local logon for untrusted users/accounts and reduce chances of low-privileged local access, then patch as soon as possible.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-41379 and every CVE in our database. Create a free account — no credit card required.
Create Free Account