Improper access control in Microsoft Windows and Windows Server - CVE-2021-36934
Published: July 21, 2021 / Updated: August 23, 2023
Vulnerability identifier: #VU55140
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-36934
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. A local user can run arbitrary code with SYSTEM privileges.
Affected software
Microsoft Windows
Windows Server
Windows Server
How to mitigate CVE-2021-36934
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
Links to Public Exploits and PoC-codes
- Exploit #9257 - CVE-2021-36934 (C# PoC for CVE-2021-36934/HiveNightmare/SeriousSAM) (August 23, 2023)
- Exploit #6772 - CVE-2021-36934-export-shadow-volume-POC () (September 21, 2021)
- Exploit #6619 - oxide_hive (Exploit for CVE-2021-36934) (August 12, 2021)
- Exploit #6612 - CVE-2021-36934_export_shadow_volume () (August 11, 2021)
- Exploit #6595 - poc_CVE-2021-36934 (POC experiments with Volume Shadow copy Service (VSS)) (August 2, 2021)
- Exploit #6581 - Windows SAM secrets leak - HiveNightmare (July 29, 2021)
- Exploit #6568 - CVE-2021-36934 () (July 26, 2021)
- Exploit #6565 - CVE-2021-36934 (C# PoC for CVE-2021-36934/HiveNightmare/SeriousSAM) (July 25, 2021)
- Exploit #6564 - ShadowSteal (Pure Nim implementation for exploiting CVE-2021-36934, the SeriousSAM local privilege escalation) (July 25, 2021)
- Exploit #6561 - HiveNightmare (HiveNightmare/SeriousSAM(CVE_2021_36934)) (July 25, 2021)
- Exploit #6558 - PyNightmare (PoC for CVE-2021-36934 Aka HiveNightmare/SeriousSAM written in python3) (July 25, 2021)
- Exploit #6553 - SeriousSam (HiveNightmare a.k.a. SeriousSam Local Privilege Escalation in Windows – CVE-2021-36934) (July 25, 2021)
- Exploit #6552 - Invoke-HiveDreams (A capability to identify and remediate CVE-2021-36934 (HiveNightmare)) (July 25, 2021)
- Exploit #6551 - Invoke-HiveNightmare (PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the SAM, Security, and Software Registry hives in Windows 10 version 1809 or newer) (July 25, 2021)