Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

nvd логотип

CVE-2021-26887

больше 5 лет назад

An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited the vulnerability would be able to begin redirecting another user's personal data to a created folder. To exploit the vulnerability, an attacker can create a new folder under the Folder Redirection root path and create a junction on a newly created User folder. When the new user logs in, Folder Redirection would start redirecting to the folder and copying personal data. This elevation of privilege vulnerability can only be addressed by reconfiguring Folder Redirection with Offline files and restricting permissions, and NOT via a security update for affected Windows Servers. See the FAQ section of this CVE for configuration guidance.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-26887

больше 5 лет назад

Microsoft Windows Folder Redirection Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xphp-jrmh-9rjj

больше 4 лет назад

Microsoft Windows Folder Redirection Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2021-01677

больше 5 лет назад

Уязвимость реализации технологии перенаправления папок Folder Redirection операционных систем Windows, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-26887

An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited the vulnerability would be able to begin redirecting another user's personal data to a created folder. To exploit the vulnerability, an attacker can create a new folder under the Folder Redirection root path and create a junction on a newly created User folder. When the new user logs in, Folder Redirection would start redirecting to the folder and copying personal data. This elevation of privilege vulnerability can only be addressed by reconfiguring Folder Redirection with Offline files and restricting permissions, and NOT via a security update for affected Windows Servers. See the FAQ section of this CVE for configuration guidance.

CVSS3: 7.8
1%
Низкий
больше 5 лет назад
msrc логотип
CVE-2021-26887

Microsoft Windows Folder Redirection Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
больше 5 лет назад
github логотип
GHSA-xphp-jrmh-9rjj

Microsoft Windows Folder Redirection Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
fstec логотип
BDU:2021-01677

Уязвимость реализации технологии перенаправления папок Folder Redirection операционных систем Windows, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.8
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу