#VU57795 Security restrictions bypass in Windows and Windows Server
Published: October 29, 2021
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to Windows User Profile Service does not properly impose security restrictions. A local unprivileged user in possession of credentials from another unprivileged account can run a specially crafted program and execute arbitrary code with SYSTEM privileges.
This vulnerability exists due to incomplete fix for #VU55695 (CVE-2021-34484).