### [CVE-2021-28313](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28313) ![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20Visual%20Studio%202015%20Update%203&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20Visual%20Studio%202017%20version%2015.9%20(includes%2015.0%20-%2015.8)&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20Visual%20Studio%202019%20version%2016.4%20(includes%2016.0%20-%2016.3)&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20Visual%20Studio%202019%20version%2016.7%20(includes%2016.0%20%E2%80%93%2016.6)&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20Visual%20Studio%202019%20version%2016.9%20(includes%2016.0%20-%2016.8)&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Version%201803&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Version%201809&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Version%201909&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Version%202004&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Version%2020H2&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202019%20(Server%20Core%20installation)&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202019&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%20version%202004&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%20version%2020H2&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%2C%20version%201909%20(Server%20Core%20installation)&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=10.0.0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=14.0.0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=15.0.0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=15.9.0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=16.0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=16.0.0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Elevation%20of%20Privilege&color=brightgreen) ### Description Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability ### POC #### Reference - http://packetstormsecurity.com/files/162251/Microsoft-DiagHub-Privilege-Escalation.html - http://seclists.org/fulldisclosure/2021/Apr/40 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/eeenvik1/scripts_for_YouTrack - https://github.com/irsl/microsoft-diaghub-case-sensitivity-eop-cve