← Global Threat Landscape

CVE-2021-36934

Critical

91.5

RPS

Description

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have the ability to execute code on a victim system to exploit this vulnerability. After installing this security update, you must manually delete all shadow copies of system files, including the SAM database, to fully mitigate this vulnerabilty. Simply installing this security update will not fully mitigate this vulnerability. See KB5005357- Delete Volume Shadow Copies.

Source: NVD

Signals

CVSS
7.8
High · v3.1
EPSS
67.25%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Feb 2022
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
Not mapped
Published
22 Jul 2021
Last modified 10 Aug 2026

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2021-36934

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2021-36934 · RPS 91.5 · DevSecure Intelligence