CVE-2021-28325
published 2021-04-13CVE-2021-28325: Windows SMB Information Disclosure Vulnerability Windows SMB Information Disclosure Vulnerability
medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
61.65%
99.1th percentile
Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1507 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < publication | publication |
| microsoft | windows_8.1 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2012 | >= 6.2.0 < publication | publication |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2016 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_2019 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < publication | publication |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1803 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
| msrc | windows_10_version_2004 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Check Point IPS blade provides a signature for this vulnerability targeting Windows SMB Information Disclosure ↗
- ·The vulnerability discloses uninitialized and kernel memory contents to a user-mode process via Windows SMB Server; exploitation is rated 'More Likely' for both latest and older software releases ↗
- ·Exploit status is publicly disclosed: No; Exploited: No; but exploitation likelihood is rated 'More Likely' for all supported software releases ↗
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
cvelistv56.5MEDIUM
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-46x8-v252-q5qw: Windows SMB Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28325
ghsa_unreviewed·2022-05-24·CVSS 6.5
CVE-2021-28324 [MEDIUM] CWE-200 GHSA-46x8-v252-q5qw: Windows SMB Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28325
Windows SMB Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28325.
GHSA
GHSA-w8mh-gxg3-xrvm: Windows SMB Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28324
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2021-28325 [HIGH] CWE-200 GHSA-w8mh-gxg3-xrvm: Windows SMB Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28324
Windows SMB Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28324.
CVEList
Windows SMB Information Disclosure Vulnerability
cvelistv5·2021-04-13·CVSS 6.5
CVE-2021-28325 [MEDIUM] Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
Microsoft
Windows SMB Information Disclosure Vulnerability
vendor_msrc·2021-04-13·CVSS 6.5
CVE-2021-28325 [MEDIUM] Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory and kernel memory - unintentional read access to memory contents in kernel space from a user mode process.
Windows SMB Server: Windows SMB Server
Microsoft: Microsoft
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5001339
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5001342
Reference: https://support.m
No detection rules found.
No public exploits indexed.
Checkpoint
19th April – Threat Intelligence Report
blogs_checkpoint·2021-04-19·CVSS 9.8
CVE-2018-13379 [CRITICAL] 19th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 19th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 19th April, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The U.S National Security Agency (NSA), the Cybersecurity and infrastructure security agency (CISA), and the Federal Bureau of Investigation (FBI) have published a joint advisory warning that a Russia-linked APT group, APT25, is exploiting five vulnerabilities in an ongoing attack against U.S targets.
Check Point IPS provide
Trendmicro
April Patch Tuesday Sets Record High for 2021
blogs_trendmicro·2021-04-13·CVSS 7.8
[HIGH] April Patch Tuesday Sets Record High for 2021
## April Patch Tuesday Sets Record High for 2021
April’s Patch Tuesday fixes 114 vulnerabilities in various Microsoft products, a slight increase from March’s 89. This is the most vulnerabilities fixed in a month for 2021 to date, as well as a slight increase from the same month last year.
By: Trend Micro Apr 13, 2021 Read time: ( words)
Save to Folio
April’s Patch Tuesday fixes 114 vulnerabilities in various Microsoft products, a slight increase from March’s 89. This is the most vulnerabilities fixed in a month for 2021 to date, as well as a slight increase from the same month last year.
Of these vulnerabilities, a total of 19 were classified as Critical by Microsoft. Four of these vulnerabilities were already publicly known, with a separate vulnerability already being exploited in t
Trendmicro
April Patch Tuesday Sets Record High for 2021
blogs_trendmicro·2021-04-13·CVSS 7.8
[HIGH] April Patch Tuesday Sets Record High for 2021
# April Patch Tuesday Sets Record High for 2021
April’s Patch Tuesday fixes 114 vulnerabilities in various Microsoft products, a slight increase from March’s 89. This is the most vulnerabilities fixed in a month for 2021 to date, as well as a slight increase from the same month last year.
By: Trend Micro
2021/04/13
Read time: ( words)
Save to Folio
April’s Patch Tuesday fixes 114 vulnerabilities in various Microsoft products, a slight increase from March’s 89. This is the most vulnerabilities fixed in a month for 2021 to date, as well as a slight increase from the same month last year.
Of these vulnerabilities, a total of 19 were classified as Critical by Microsoft. Four of these vulnerabilities were already publicly known, with a separate vulnerability already being exploited in the
Trendmicro
April Patch Tuesday Sets Record High for 2021
blogs_trendmicro·2021-04-13·CVSS 7.8
[HIGH] April Patch Tuesday Sets Record High for 2021
## April Patch Tuesday Sets Record High for 2021
April’s Patch Tuesday fixes 114 vulnerabilities in various Microsoft products, a slight increase from March’s 89. This is the most vulnerabilities fixed in a month for 2021 to date, as well as a slight increase from the same month last year.
By: Trend Micro 2021/04/13 Read time: ( words)
Save to Folio
April’s Patch Tuesday fixes 114 vulnerabilities in various Microsoft products, a slight increase from March’s 89. This is the most vulnerabilities fixed in a month for 2021 to date, as well as a slight increase from the same month last year.
Of these vulnerabilities, a total of 19 were classified as Critical by Microsoft. Four of these vulnerabilities were already publicly known, with a separate vulnerability already being exploited in the
Crowdstrike
2021 April Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] 2021 April Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
2021 April Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] 2021 April Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
2021-04-13
Published