CVE-2021-26881
published 2021-03-11CVE-2021-26881: Microsoft Windows Media Foundation Remote Code Execution Vulnerability
PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.62%
84.6th percentile
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.18874 | 10.0.10240.18874 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.4283 | 10.0.14393.4283 |
| microsoft | windows_10_version_1803 | >= 10.0.0 < 10.0.17134.2087 | 10.0.17134.2087 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.1817 | 10.0.17763.1817 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.1817 | 10.0.17763.1817 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.1440 | 10.0.18363.1440 |
| microsoft | windows_10_version_2004 | >= 10.0.0 < 10.0.19043.867 | 10.0.19043.867 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19043.867 | 10.0.19043.867 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.24566 | 6.1.7601.24566 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.24566 | 6.1.7601.24566 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.19968 | 6.3.9600.19968 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.24566 | 6.1.7601.24566 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23298 | 6.2.9200.23298 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.19968 | 6.3.9600.19968 |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 7.5
CVE-2021-26881 [HIGH] Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Windows Media: Windows Media
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5000809
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5000822
Reference: https://support.microsoft.com/help/5000822
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5000808
Reference: https://support.microsoft.com/help/5000808
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5000802
Reference: https://support.microsoft.com/help/5000802
VulDB
Microsoft Windows up to Server 2019 Media Foundation privilege escalation
vuldb·2026-08-20·CVSS 8.8
CVE-2021-26881 [HIGH] Microsoft Windows up to Server 2019 Media Foundation privilege escalation
A vulnerability identified as critical has been detected in Microsoft Windows. This issue affects some unknown processing of the component Media Foundation. This manipulation causes privilege escalation.
This vulnerability is tracked as CVE-2021-26881. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to install a patch to address this issue.
GHSA
GHSA-2rp6-pc7c-f2rv: Microsoft Windows Media Foundation Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-26881 [HIGH] GHSA-2rp6-pc7c-f2rv: Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-03-11
Published