⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2021-11-17. Required action: Apply updates per vendor instructions..

CVE-2021-36948

Severity
7.8HIGH
EPSS
1.1%
top 22.42%
CISA KEV
KEV
Added 2021-11-03
Due 2021-11-17
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedAug 12
KEV addedNov 3
KEV dueNov 17
Latest updateMay 24
CISA Required Action: Apply updates per vendor instructions.

Description

Windows Update Medic Service Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages15 packages

NVDmicrosoft/windows< 10.0.19041.1165+2
NVDmicrosoft/windows_10_1809< 10.0.17763.2114
NVDmicrosoft/windows_10_1909< 10.0.18363.1734
NVDmicrosoft/windows_10_2004< 10.0.19041.1165
NVDmicrosoft/windows_10_20h2< 10.0.19042.1165

Patches

🔴Vulnerability Details

4
GHSA
GHSA-fcr2-qx8m-pfhp: Windows Update Medic Service Elevation of Privilege Vulnerability2022-05-24
Project0
The More You Know, The More You Know You Don’t Know - Project Zero2022-04-01
CVEList
Windows Update Medic Service Elevation of Privilege Vulnerability2021-08-12
VulnCheck
Microsoft Windows Update Medic Service Privilege Escalation Vulnerability2021

📋Vendor Advisories

2
CISA
Microsoft Windows Update Medic Service Privilege Escalation Vulnerability2021-11-03
Microsoft
Windows Update Medic Service Elevation of Privilege Vulnerability2021-08-10

🕵️Threat Intelligence

2
Krebs
Microsoft Patch Tuesday, August 2021 Edition2021-08-10
Krebs
Microsoft Patch Tuesday, August 2021 Edition2021-08-10
CVE-2021-36948 (HIGH CVSS 7.8) | Windows Update Medic Service Elevat | cvebase.io