Windows File Server Resource Management Service Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What privileges could be gained by an attacker who successfully exploited the vulnerability? An attacker would only be able to delete targeted files on a system.
How could an attacker exploit this vulnerability? To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then trigger an event that could exploit the vulnerability and save an invalid state to a database or trigger other unintended actions.
According to the CVSS metric, user interaction is required (UI:R) and privileges required is Low (PR:L). What does that mean for this vulnerability? An authorized attacker with guest privileges must send a victim a malicious site and convince them to open it.
🎯 Affected products17
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
- Windows Server 2022, 23H2 Edition (Server Core installation)
✅ Remediation
KB5036896 (Security Update) — fixed build 10.0.17763.5696 KB5036909 (Security Update) — fixed build 10.0.20348.2402 KB5036910 (Security Update) — fixed build 10.0.25398.830 KB5036899 (Security Update) — fixed build 10.0.14393.6897 KB5036932 (Monthly Rollup) — fixed build 6.0.6003.22618 KB5036950 (Security Only) — fixed build 6.0.6003.22618 KB5036967 (Monthly Rollup) — fixed build 6.1.7601.27067 KB5036922 (Security Only) — fixed build 6.1.7601.27067 KB5036969 (Monthly Rollup) — fixed build 6.2.9200.24821 KB5036960 (Monthly Rollup) — fixed build 6.3.9600.21924
🔗 References (21)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26216
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5036896
- referencehttps://support.microsoft.com/help/5036896
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5036909
- referencehttps://support.microsoft.com/help/5036909
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5036910
- referencehttps://support.microsoft.com/help/5036910
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5036899
- referencehttps://support.microsoft.com/help/5036899
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5036932
- referencehttps://support.microsoft.com/help/5036932
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5036950
- referencehttps://support.microsoft.com/help/5036950
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5036967
- referencehttps://support.microsoft.com/help/5036967
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5036922
- referencehttps://support.microsoft.com/help/5036922
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5036969
- referencehttps://support.microsoft.com/help/5036969
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5036960
- referencehttps://support.microsoft.com/help/5036960