CVE-2021-26890
published 2021-03-11CVE-2021-26890: Application Virtualization Remote Code Execution Vulnerability
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.79%
53.7th percentile
Application Virtualization Remote Code Execution Vulnerability
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.1817 | 10.0.17763.1817 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.1817 | 10.0.17763.1817 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.1440 | 10.0.18363.1440 |
| microsoft | windows_10_version_2004 | >= 10.0.0 < 10.0.19043.867 | 10.0.19043.867 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19043.867 | 10.0.19043.867 |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.1817 | 10.0.17763.1817 |
| microsoft | windows_server_version_2004 | >= 10.0.0 < 10.0.19043.867 | 10.0.19043.867 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19043.867 | 10.0.19043.867 |
| msrc | windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_10_version_1909_for_32-bit_systems | — | — |
| msrc | windows_10_version_1909_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1909_for_x64-based_systems | — | — |
| msrc | windows_10_version_2004_for_32-bit_systems | — | — |
| msrc | windows_10_version_2004_for_arm64-based_systems | — | — |
| msrc | windows_10_version_2004_for_x64-based_systems | — | — |
| msrc | windows_10_version_20h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_20h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_20h2_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Windows up to Server 2019 Application Virtualization code injection
vuldb·2026-08-20·CVSS 7.8
CVE-2021-26890 [HIGH] Microsoft Windows up to Server 2019 Application Virtualization code injection
A vulnerability categorized as critical has been discovered in Microsoft Windows up to Server 2019. Affected is an unknown function of the component Application Virtualization. Such manipulation leads to code injection.
This vulnerability is documented as CVE-2021-26890. The attack can be executed remotely. There is not any exploit available.
A patch should be applied to remediate this issue.
GHSA
GHSA-2g74-jg6p-c4x3: Application Virtualization Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-26890 [HIGH] CWE-94 GHSA-2g74-jg6p-c4x3: Application Virtualization Remote Code Execution Vulnerability
Application Virtualization Remote Code Execution Vulnerability
Microsoft
Application Virtualization Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 7.8
CVE-2021-26890 [HIGH] Application Virtualization Remote Code Execution Vulnerability
Application Virtualization Remote Code Execution Vulnerability
Application Virtualization: Application Virtualization
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5000822
Reference: https://support.microsoft.com/help/5000822
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5000808
Reference: https://support.microsoft.com/help/5000808
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5000802
Reference: https://support.microsoft.com/help/5000802
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-03-11
Published