CVE-2021-28324
published 2021-04-13CVE-2021-28324: Windows SMB Information Disclosure Vulnerability Windows SMB Information Disclosure Vulnerability
high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
6.22%
92.7th percentile
Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < publication | publication |
| msrc | windows_10_version_2004_for_32-bit_systems | — | — |
| msrc | windows_10_version_2004_for_arm64-based_systems | — | — |
| msrc | windows_10_version_2004_for_x64-based_systems | — | — |
| msrc | windows_10_version_20h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_20h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_20h2_for_x64-based_systems | — | — |
| msrc | windows_server_version_2004 | — | — |
| msrc | windows_server_version_20h2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target component is Windows SMB Server; monitor for anomalous SMB traffic that may trigger uninitialized/kernel memory reads from user-mode processes ↗
- →Exploitation assessed as 'More Likely' for both latest and older software releases; prioritize detection on unpatched Windows SMB Server instances ↗
- ·No public exploit or active in-the-wild exploitation confirmed at time of advisory publication ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
cvelistv57.5HIGH
vulncheck7.5HIGH
vendor_msrc7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-46x8-v252-q5qw: Windows SMB Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28325
ghsa_unreviewed·2022-05-24·CVSS 6.5
CVE-2021-28324 [MEDIUM] CWE-200 GHSA-46x8-v252-q5qw: Windows SMB Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28325
Windows SMB Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28325.
GHSA
GHSA-w8mh-gxg3-xrvm: Windows SMB Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28324
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2021-28325 [HIGH] CWE-200 GHSA-w8mh-gxg3-xrvm: Windows SMB Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28324
Windows SMB Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28324.
CVEList
Windows SMB Information Disclosure Vulnerability
cvelistv5·2021-04-13·CVSS 7.5
CVE-2021-28324 [HIGH] Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
VulnCheck
Windows SMB Information Disclosure Vulnerability
vulncheck·2021·CVSS 7.5
CVE-2021-28324 [HIGH] Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
Affected: Microsoft Windows
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://go.catonetworks.com/rs/245-RJK-441/images/security%20Quarterly%20Report%20q2.pdf
Microsoft
Windows SMB Information Disclosure Vulnerability
vendor_msrc·2021-04-13·CVSS 7.5
CVE-2021-28324 [HIGH] Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory and kernel memory - unintentional read access to memory contents in kernel space from a user mode process.
Windows SMB Server: Windows SMB Server
Microsoft: Microsoft
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5001330
Reference: https://support.microsoft.com/help/5001330
No detection rules found.
No public exploits indexed.
Trendmicro
April Patch Tuesday Sets Record High for 2021
blogs_trendmicro·2021-04-13·CVSS 7.8
[HIGH] April Patch Tuesday Sets Record High for 2021
## April Patch Tuesday Sets Record High for 2021
April’s Patch Tuesday fixes 114 vulnerabilities in various Microsoft products, a slight increase from March’s 89. This is the most vulnerabilities fixed in a month for 2021 to date, as well as a slight increase from the same month last year.
By: Trend Micro Apr 13, 2021 Read time: ( words)
Save to Folio
April’s Patch Tuesday fixes 114 vulnerabilities in various Microsoft products, a slight increase from March’s 89. This is the most vulnerabilities fixed in a month for 2021 to date, as well as a slight increase from the same month last year.
Of these vulnerabilities, a total of 19 were classified as Critical by Microsoft. Four of these vulnerabilities were already publicly known, with a separate vulnerability already being exploited in t
Trendmicro
April Patch Tuesday Sets Record High for 2021
blogs_trendmicro·2021-04-13·CVSS 7.8
[HIGH] April Patch Tuesday Sets Record High for 2021
# April Patch Tuesday Sets Record High for 2021
April’s Patch Tuesday fixes 114 vulnerabilities in various Microsoft products, a slight increase from March’s 89. This is the most vulnerabilities fixed in a month for 2021 to date, as well as a slight increase from the same month last year.
By: Trend Micro
2021/04/13
Read time: ( words)
Save to Folio
April’s Patch Tuesday fixes 114 vulnerabilities in various Microsoft products, a slight increase from March’s 89. This is the most vulnerabilities fixed in a month for 2021 to date, as well as a slight increase from the same month last year.
Of these vulnerabilities, a total of 19 were classified as Critical by Microsoft. Four of these vulnerabilities were already publicly known, with a separate vulnerability already being exploited in the
Trendmicro
April Patch Tuesday Sets Record High for 2021
blogs_trendmicro·2021-04-13·CVSS 7.8
[HIGH] April Patch Tuesday Sets Record High for 2021
## April Patch Tuesday Sets Record High for 2021
April’s Patch Tuesday fixes 114 vulnerabilities in various Microsoft products, a slight increase from March’s 89. This is the most vulnerabilities fixed in a month for 2021 to date, as well as a slight increase from the same month last year.
By: Trend Micro 2021/04/13 Read time: ( words)
Save to Folio
April’s Patch Tuesday fixes 114 vulnerabilities in various Microsoft products, a slight increase from March’s 89. This is the most vulnerabilities fixed in a month for 2021 to date, as well as a slight increase from the same month last year.
Of these vulnerabilities, a total of 19 were classified as Critical by Microsoft. Four of these vulnerabilities were already publicly known, with a separate vulnerability already being exploited in the
2021-04-13
Published
Exploited in the wild