CVE-2021-26870
published 2021-03-11CVE-2021-26870: Windows Projected File System Elevation of Privilege Vulnerability
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.60%
45.0th percentile
Windows Projected File System Elevation of Privilege Vulnerability
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ammonia_project | ammonia | >= 0 < 2.1.3 | 2.1.3 |
| ammonia_project | ammonia | >= 3.0.0 < 3.1.0 | 3.1.0 |
| github.com | gotify_server | >= 0 < 2.2.3 | 2.2.3 |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2019 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < publication | publication |
| msrc | windows_10_version_1803_for_32-bit_systems | — | — |
| msrc | windows_10_version_1803_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1803_for_x64-based_systems | — | — |
| msrc | windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
ghsa6.1MEDIUM
vendor_msrc7.8HIGH
vendor_oracle5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Application Express Application Builder (DOMPurify) — CVE-2020-26870
vendor_oracle·2021-07-15·CVSS 5.4
CVE-2020-26870 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Oracle Application Express Application Builder (DOMPurify) — CVE-2020-26870
Oracle Oracle Database Server Risk Matrix: Oracle Application Express Application Builder (DOMPurify) vulnerability
CVE: CVE-2020-26870
CVSS: 5.4
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Microsoft
Windows Projected File System Elevation of Privilege Vulnerability
vendor_msrc·2021-03-09·CVSS 7.8
CVE-2021-26870 [HIGH] Windows Projected File System Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
Windows Projected File System Filter Driver: Windows Projected File System Filter Driver
Microsoft: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5000809
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5000822
Reference: https://support.microsoft.com/help/5000822
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5000808
Reference: https://support.microsoft.com/help/5000808
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB500080
GHSA
Reflected XSS in Gotify's /docs via import of outdated Swagger UI
ghsa·2023-01-10·CVSS 6.1
[MEDIUM] CWE-79 Reflected XSS in Gotify's /docs via import of outdated Swagger UI
Reflected XSS in Gotify's /docs via import of outdated Swagger UI
### Impact
Gotify exposes an outdated instance of the [Swagger UI](https://swagger.io/tools/swagger-ui/) API documentation frontend at `/docs` which is susceptible to reflected XSS attacks when loading external Swagger config files.
Specifically, the DOMPurify version included with this version of Swagger UI is vulnerable to a [rendering XSS](https://www.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/) incorporating the mutation payload detailed in [CVE-2020-26870](https://research.securitum.com/mutation-xss-via-mathml-mutation-dompurify-2-0-17-bypass/) which was patched in 2021. This is further tracked in the GitHub Advisory Database as GHSA-QRMM-W75W-3WPX.
An attacker can execute arbitrary Java
GHSA
GHSA-3c8c-qvfq-8x38: Windows Projected File System Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-26870 [HIGH] CWE-269 GHSA-3c8c-qvfq-8x38: Windows Projected File System Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
GHSA
Cross-site Scripting in ammonia
ghsa·2021-08-25·CVSS 6.1
CVE-2021-38193 [MEDIUM] CWE-79 Cross-site Scripting in ammonia
Cross-site Scripting in ammonia
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-03-11
Published