cbcvebase.
CVE-2021-36942
published 2021-08-12

CVE-2021-36942: Windows LSA Spoofing Vulnerability Windows LSA Spoofing Vulnerability

high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
66.02%
99.2th percentile
Windows LSA Spoofing Vulnerability Windows LSA Spoofing Vulnerability

Affected

18 ranges
VendorProductVersion rangeFixed in
microsoftwindows_server_2008_r2_service_pack_1>= 6.0.0 < 6.1.7601.256856.1.7601.25685
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.0 < 6.1.7601.256856.1.7601.25685
microsoftwindows_server_2008_service_pack_2>= 6.0.0 < 6.0.6003.211926.0.6003.21192
microsoftwindows_server_2012>= 6.2.0 < 6.2.9200.234356.2.9200.23435
microsoftwindows_server_2012_r2>= 6.3.0 < 6.3.9600.200946.3.9600.20094
microsoftwindows_server_2016>= 10.0.0 < 10.0.14393.458310.0.14393.4583
microsoftwindows_server_2019>= 10.0.0 < 10.0.17763.211410.0.17763.2114
microsoftwindows_server_version_2004>= 10.0.0 < 10.0.19041.116510.0.19041.1165
microsoftwindows_server_version_20h2>= 10.0.0 < 10.0.19042.116510.0.19042.1165
msrcwindows_server_2008_for_32-bit_systems_service_pack_2
msrcwindows_server_2008_for_x64-based_systems_service_pack_2
msrcwindows_server_2008_r2_for_x64-based_systems_service_pack_1
msrcwindows_server_2012
msrcwindows_server_2012_r2
msrcwindows_server_2016
msrcwindows_server_2019
msrcwindows_server_version_2004
msrcwindows_server_version_20h2

Detection & IOCsextracted from sources · hover to see the quote

otherMS-EFSR (Encrypting File System Remote Protocol)
ip172.17.XX.XX
processElfrOpenBELW
otherMS-EVEN (EventLog Remoting Protocol)
  • Alert on use of the ElfrOpenBELW RPC opnum (MS-EVEN interface) when the UNC/IP path parameter resolves to an external or non-standard IP address, as this is a rare coercion vector used in real-world attacks.
  • Baseline MS-EVEN RPC usage per host; alert on any host invoking MS-EVEN against a destination not seen in the prior 30 days, especially toward external IPs.
  • Monitor for RPC calls carrying UNC path parameters (e.g., \\share\path\to\file) that resolve to external or attacker-controlled IP addresses, as authentication coercion tools embed the attacker's listener address in these parameters.
  • Prioritize detection of PetitPotam tool usage targeting MS-EFSR; also monitor lesser-known coercion tools: DFSCoerce (MS-DFSNM), ShadowCoerce (MS-FSRVP), CheeseOunce (MS-EVEN), and PrinterBug (MS-RPRN).
  • Domain Controllers should be treated as highest-priority targets for patching and monitoring; coercion attacks specifically target DCs to obtain NTLM credentials that can be relayed for remote code execution.
  • ·CVE-2021-36942 (PetitPotam) exploits a legitimate Windows RPC feature (MS-EFSR) and requires no special permissions, meaning standard low-privileged domain user accounts can trigger authentication coercion.
  • ·Attackers are pivoting to lesser-known RPC opnums (beyond the well-known PetitPotam/MS-EFSR vector) to evade defenses tuned only for known coercion interfaces; over 240 RPC functions remain untested for coercion potential.
  • ·Ready-to-use exploit code for PetitPotam is integrated into penetration testing frameworks like Metasploit and used alongside tools like Mimikatz, significantly lowering the barrier to entry for attackers.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
cvelistv57.5HIGH
vulncheck7.5HIGH
cisa7.5HIGH
vendor_msrc7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.