How to Address the SeriousSAM Vulnerability in Microsoft Windows 10 and 11
On July 26, 2021, a critical unpatched vulnerability affecting Microsoft Windows 10 and 11 was publicly disclosed. Known as SeriousSAM, this vulnerability enables attackers with low-level permissions to access sensitive system files, potentially leading to Pass-the-Hash and Silver Ticket attacks. Exploiting this flaw can allow attackers to access hashed passwords within the Security Account Manager (SAM) and the Registry, ultimately enabling them to execute arbitrary code with SYSTEM privileges.
The SeriousSAM vulnerability, identified as CVE-2021-36934, is present in the default settings of Windows 10 and 11 due to a configuration that grants ‘read’ permissions to the built-in users group, which includes all local users. Consequently, these users can access SAM files and the Registry, allowing them to view password hashes. With ‘User’ access, attackers can utilize tools like Mimikatz to further exploit the system.
Security Alert: Exposure of SeriousSAM Vulnerability in Windows 10 and 11 July 26, 2021 A newly disclosed vulnerability, dubbed SeriousSAM, poses significant risks to users of Microsoft Windows 10 and Windows 11. This unpatched flaw enables attackers with minimal privileges to gain access to critical Windows system files, potentially leading…
How to Address the SeriousSAM Vulnerability in Microsoft Windows 10 and 11
On July 26, 2021, a critical unpatched vulnerability affecting Microsoft Windows 10 and 11 was publicly disclosed. Known as SeriousSAM, this vulnerability enables attackers with low-level permissions to access sensitive system files, potentially leading to Pass-the-Hash and Silver Ticket attacks. Exploiting this flaw can allow attackers to access hashed passwords within the Security Account Manager (SAM) and the Registry, ultimately enabling them to execute arbitrary code with SYSTEM privileges.
The SeriousSAM vulnerability, identified as CVE-2021-36934, is present in the default settings of Windows 10 and 11 due to a configuration that grants ‘read’ permissions to the built-in users group, which includes all local users. Consequently, these users can access SAM files and the Registry, allowing them to view password hashes. With ‘User’ access, attackers can utilize tools like Mimikatz to further exploit the system.