Nasty Windows 10 vulnerability gets a patch, but not from Microsoft

Representational image depecting cybersecurity protection
(Image credit: Shutterstock)

Cybersecurity researchers have released an unofficial patch for a bug in Windows 10, originally reported to Microsoft in October 2020, which later research revealed could take the form of a local privilege vulnerability as well.

Issuing the free micropatch, Mitja Kolsek, co-founder of the 0patch micropatching service, explains that it too overlooked the vulnerability initially since it was disclosed as an information disclosure bug, which normally isn’t critical enough to warrant attention from 0patch.

The vulnerability, tracked as CVE-2021-24084, was discovered by security researcher Abdelhamid Naceri, who blogged about it in June 2021, detailing its working and noting how it hadn’t yet been fixed by Microsoft. 

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

An upgraded bug

Kolsek banks on a fixed Windows privilege escalation vulnerability, tracked as CVE 2021-36934, to suggest that under certain specific conditions, an arbitrary file disclosure can be upgraded and abused for local privilege escalation.

“In November, however, Abdelhamid pointed out that this - still unpatched - bug may not be just an information disclosure issue, but a local privilege escalation vulnerability….We confirmed this by using the procedure described in this blog post by Raj Chandel in conjunction with Abdelhamid's bug - and being able to run code as local administrator,” writes Kolsek, explaining the need to patch the bug.

The unofficial micropatch will work on all affected Windows 10 versions, and as is usual,  will be available for free until Microsoft releases an official fix for the issue.  

Ensure your systems remain secure and updated using one of these best patch management tools

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Representational image of a cybercriminal
Microsoft discovers five potentially damaging attacks against its own software
Avast cybersecurity
An unpatched Windows zero-day flaw has been exploited by 11 nation-state attackers
Representational image of a cybercriminal
Microsoft just patched a host of worrying security issues, so update now
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
A hacker wearing a hoodie sitting at a computer, his face hidden.
Microsoft patches three worrying security flaws in its latest critical update, so update now
A person at a laptop with a cybersecure lock symbol floating above it.
Parallels Desktop has some worrying security flaws for Mac users
Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That&#039;s Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS
Marvel Rivals
Marvel Rivals will get two new hero skins for Moon Knight and Black Panther this week meaning I'll now need to farm even more Units
Netflix Ads
Netflix adds HDR10+ support – great news for Samsung TV owners, but don't expect LG and Sony to do the same any time soon
Klipsch Klipschorn AK7 in a room with lots of dark wood furniture and a bare brick wall
Klipsch just updated two of its most iconic stereo speaker designs, keeping these beautiful retro icons on your most-wanted list