Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-28321 | patch vendor advisory |
http://seclists.org/fulldisclosure/2021/Apr/40 | third party advisory mailing list |
http://packetstormsecurity.com/files/162251/Microsoft-DiagHub-Privilege-Escalation.html | vdb entry third party advisory |