CVE-2021-26887
Last modified
CVE-2021-26887 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited the vulnerability would be able to begin redirecting another user's personal data to a created folder. To exploit the vulnerability, an attacker can create a new folder under the Folder Redirection root path and create a junction on a newly created User folder. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited the vulnerability would be able to begin redirecting another user's personal data to a created folder. To exploit the vulnerability, an attacker can create a new folder under the Folder Redirection root path and create a junction on a newly created User folder. When the new user logs in, Folder Redirection would start redirecting to the folder and copying personal data. This elevation of privilege vulnerability can only be addressed by reconfiguring Folder Redirection with Offline files and restricting permissions, and NOT via a security update for affected Windows Servers. See the FAQ section of this CVE for configuration guidance.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Windows 10 | All versions | — |
| Microsoft | Windows 10 | 20h2 | — |
| Microsoft | Windows 10 | 1607 | — |
| Microsoft | Windows 10 | 1803 | — |
| Microsoft | Windows 10 | 1809 | — |
| Microsoft | Windows 10 | 1909 | — |
| Microsoft | Windows 10 | 2004 | — |
| Microsoft | Windows 7 | All versions | Sp1 |
| Microsoft | Windows 8.1 | All versions | — |
| Microsoft | Windows Rt 8.1 | All versions | — |
| Microsoft | Windows Server 2008 | All versions | Sp2 |
| Microsoft | Windows Server 2008 | r2 | Sp1 |
| Microsoft | Windows Server 2012 | All versions | — |
| Microsoft | Windows Server 2012 | r2 | — |
| Microsoft | Windows Server 2016 | All versions | — |
| Microsoft | Windows Server 2016 | 20h2 | — |
| Microsoft | Windows Server 2016 | 1909 | — |
| Microsoft | Windows Server 2016 | 2004 | — |
| Microsoft | Windows Server 2019 | All versions | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-26887?
How severe is CVE-2021-26887?
How do I fix CVE-2021-26887?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-26880Windows Storage Spaces Controller Elevation of Privilege Vul…7.8
- CVE-2021-26881Microsoft Windows Media Foundation Remote Code Execution Vul…7.5
- CVE-2021-26882Remote Access API Elevation of Privilege Vulnerability7.8
- CVE-2021-26884Windows Media Photo Codec Information Disclosure Vulnerabili…5.5
- CVE-2021-26885Windows WalletService Elevation of Privilege Vulnerability7.8
- CVE-2021-26886User Profile Service Denial of Service Vulnerability6.1
- CVE-2021-26889Windows Update Stack Elevation of Privilege Vulnerability7.8
- CVE-2021-26890Application Virtualization Remote Code Execution Vulnerabili…7.8
- CVE-2021-26891Windows Container Execution Agent Elevation of Privilege Vul…7.8
- CVE-2021-26892Windows Extensible Firmware Interface Security Feature Bypas…6.2
- CVE-2021-26893Windows DNS Server Remote Code Execution Vulnerability9.8
- CVE-2021-26894Windows DNS Server Remote Code Execution Vulnerability9.8
Are you affected by CVE-2021-26887?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
