Cyber Resilience

CVE-2021-36934

Microsoft Windows 10 1809 ≤ 10.0.17763.2114

CISA KEVActive ExploitationEUVD ExploitedPublic PoC
Published
22 July 2021
Modified
10 August 2026
KEV Added
10 February 2022
Patch / advisory
CVSS Score v3.1 7.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.67 99.2th percentile
Risk Priority 83 floored blend · peak EPSS

Summary

CVE-2021-36934 is a high-severity an unspecified weakness vulnerability in Microsoft Windows 10 1809. Its CVSS base score is 7.8 (High).

Operationally, ranked in the top 0.8% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2021-36934 is an elevation-of-privilege vulnerability in Windows caused by overly permissive Access Control Lists on multiple system files, including the Security Accounts Manager (SAM) database. Successful exploitation allows an attacker to run arbitrary code with SYSTEM-level privileges on the affected system.

An attacker must already be able to execute code on the victim machine. Once exploited, the attacker can install programs, view or modify data, delete files, and create new accounts with full administrative rights. The CVSS 3.1 base score is 7.8 with a local attack vector, low attack complexity, and low privileges required.

Microsoft’s advisory states that the security update alone does not fully remediate the issue; administrators must also manually delete all Volume Shadow Copies of the affected system files, including the SAM database, as described in KB5005357. Public exploit code released under the names HiveNightmare and SeriousSAM demonstrates the flaw using standard user privileges to read sensitive registry hives from shadow copies.

EU & UK References

Vulnerability Data

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An…

more

attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have the ability to execute code on a victim system to exploit this vulnerability. After installing this security update, you must manually delete all shadow copies of system files, including the SAM database, to fully mitigate this vulnerabilty. Simply installing this security update will not fully mitigate this vulnerability. See KB5005357- Delete Volume Shadow Copies.

CWE(s)
KEV Date Added
10 February 2022

Related Threats

CVEs Like This One

CVE-2021-31955Same product: Microsoft Windows 10 1809both on KEV
CVE-2021-34486Same product: Microsoft Windows 10 1809both on KEV
CVE-2021-36948Same product: Microsoft Windows 10 1809both on KEV
CVE-2021-33739Same product: Microsoft Windows 10 1909both on KEV
CVE-2021-27085Same product: Microsoft Windows 10 1809both on KEV
CVE-2021-40450Same product: Microsoft Windows 10 1809both on KEV
CVE-2021-43890Same product: Microsoft Windows 10 1809both on KEV
CVE-2022-21971Same product: Microsoft Windows 10 1809both on KEV
CVE-2022-21882Same product: Microsoft Windows 10 1809both on KEV
CVE-2021-28310Same product: Microsoft Windows 10 1809both on KEV

Affected Assets

microsoft
windows 10 1809
≤ 10.0.17763.2114
microsoft
windows 10 1909
≤ 10.0.18363.1734
microsoft
windows 10 2004
≤ 10.0.19041.1165
microsoft
windows 10 20h2
≤ 10.0.19042.1165
microsoft
windows 10 21h1
≤ 10.0.19043.1165

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References