Vulnerability record · CVE-2021-41379 · published 10 November 2021
CVE-2021-41379: Windows Installer link-following elevation of privilege
Microsoft · Windows 10 1507
CVE-2021-41379 is a link-following (CWE-59) flaw in the Microsoft Windows Installer that allows a local user to gain elevated privileges. It affects a broad set of Windows client and server releases, and Microsoft published patches in November 2021. Because it is a local privilege escalation with a known public exploit history, it is a standard step in post-compromise escalation and ransomware chains.
Description
Windows Installer Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityIt is a locally exploitable privilege escalation listed in CISA KEV with known ransomware use and a high EPSS percentile, though it requires an existing foothold and has a moderate CVSS base score.
What it is
CVE-2021-41379 is a link-following (CWE-59) flaw in the Microsoft Windows Installer that allows a local user to gain elevated privileges. It affects a broad set of Windows client and server releases, and Microsoft published patches in November 2021. Because it is a local privilege escalation with a known public exploit history, it is a standard step in post-compromise escalation and ransomware chains.
Impact
An attacker who already has a foothold on a host can escalate from a low-privileged account to SYSTEM or administrative rights. That level of access enables credential theft, disabling of defenses, and further lateral movement or ransomware deployment.
Attack surface
The vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the attacker must already be able to run code on the target machine. It is not remotely reachable and does not require a victim to open a file or click anything.
Exploitation
CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03 with a due date of 2022-03-17 and flags known ransomware campaign use. EPSS gives a 30-day exploitation probability of about 19.5 percent (97th percentile), and references include vendor patch advisories and a third-party advisory.
What to do
- Apply the Microsoft security updates for CVE-2021-41379 on all affected Windows client and server versions; prioritize internet-facing and high-value hosts.
- Track remediation against the CISA KEV due date and confirm patched status rather than relying on version strings alone.
- Restrict local interactive and service logon rights to the minimum necessary to reduce the pool of accounts that can trigger the flaw.
- Monitor for and block untrusted MSI/installer execution and unexpected writes to privileged installer paths where feasible.
Detection
- Hunt for unexpected child processes spawned by msiexec.exe or the Windows Installer service, especially those running as SYSTEM.
- Alert on creation of files or directories in privileged installer-related paths by non-administrative users.
- Correlate local privilege escalation activity with subsequent credential dumping, defense evasion, or ransomware precursor behavior.
- Review Windows Installer and process creation logs for anomalous installer activity on hosts where low-privileged users can execute code.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-41379 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Windows Installer Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.
Affected products
18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41379 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41379 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-1308/ | Third Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-41379 | US Government Resource |
Track CVE-2021-41379 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-41379), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.