Security readout for executives and security teams
Plain-English summary
CVE-2021-34484 is a Windows privilege escalation flaw in the User Profile Service. An attacker already able to run low-privileged code locally could potentially gain higher privileges. CISA lists it in KEV, so organizations should treat unpatched affected Windows systems as a real-world risk.
Executive priority
High priority. This is not a remote entry-point vulnerability, but KEV listing means it has been exploited and can turn limited local access into broader system control. Remediate through normal emergency patch governance for affected Windows assets.
Technical view
The CVSS 3.1 vector is 7.8 high: local attack, low complexity, low privileges required, no user interaction, unchanged scope, and high confidentiality, integrity, and availability impact. The source bundle identifies affected Windows client and server versions, including Server Core installations.
Likely exposure
Exposure is mainly Windows desktops and servers running the listed affected versions, including Windows 10 releases, Windows 7/8.1, Windows Server 2008/2016/2019, and Server 2004/20H2 builds. Internet exposure is not indicated by the CVSS vector.
Exploitation context
CISA KEV status supports known exploitation. The bundle does not provide campaign details, exploited product build details, or public exploit mechanics. The vulnerability requires local access with low privileges, making it most relevant after initial compromise or insider misuse.
Researcher notes
Evidence supports local privilege escalation in Windows User Profile Service with official remediation available. The provided sources do not describe root cause, exploit primitives, indicators of compromise, or bypass-specific mitigations, so validation should focus on affected-version inventory and patch state.
Mitigation direction
- Apply Microsoft security updates for affected Windows versions per the MSRC advisory.
- Prioritize KEV-driven remediation on servers, shared workstations, and privileged admin endpoints.
- Review unsupported or legacy Windows assets for upgrade, isolation, or vendor-supported servicing.
- Use least privilege to reduce the number of users who can trigger local escalation paths.
- Check vendor guidance before relying on compensating controls.
Validation and detection
- Inventory Windows versions against the affected product list and CPE build information.
- Confirm patch compliance using Microsoft update records or endpoint management tooling.
- Verify Server Core and legacy Windows assets are included in remediation tracking.
- Flag systems still matching affected builds after patch windows for escalation.
- Document exceptions with compensating controls and an owner.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Privilege behavior lookup
The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2021-34484 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.8 (3.1)
- Known Exploited
- Yes
- Published
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CISA KEV status
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C1.85.9Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.8HighVector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Source materials
- CVE List V5 sourceCVE List V5
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34484CVE reference · x_refsource_MISC
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-34484CVE reference · government-resource
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
