CVE-2021-38666
published 2021-11-10CVE-2021-38666: Remote Desktop Client Remote Code Execution Vulnerability
PriorityP258high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
12.95%
95.9th percentile
Remote Desktop Client Remote Code Execution Vulnerability
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | remote_desktop_client_for_windows_desktop | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.0 < 10.0.10240.19119 | 10.0.10240.19119 |
| microsoft | windows_10_version_1607 | >= 10.0.0 < 10.0.14393.4770 | 10.0.14393.4770 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2300 | 10.0.17763.2300 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.1916 | 10.0.18363.1916 |
| microsoft | windows_10_version_2004 | >= 10.0.0 < 10.0.19041.1348 | 10.0.19041.1348 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1348 | 10.0.19042.1348 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1348 | 10.0.19043.1348 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.318 | 10.0.22000.318 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25769 | 6.1.7601.25769 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25769 | 6.1.7601.25769 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20174 | 6.3.9600.20174 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < 6.1.7601.25769 | 6.1.7601.25769 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < 6.1.7601.25769 | 6.1.7601.25769 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < 6.0.6003.21282 | 6.0.6003.21282 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.0 < 6.2.9200.23517 | 6.2.9200.23517 |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < 6.3.9600.20174 | 6.3.9600.20174 |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
58519
snort↗
58520
snort↗
58539
snort↗
58540
snort↗
58541
snort↗
300054
- →CVE-2021-38666 is exploited via a malicious attacker-controlled Remote Desktop Server; monitor for RDP client connections to untrusted/external RDP servers, especially where the client initiates outbound RDP (TCP 3389) to unknown hosts. ↗
- →Microsoft's Exploitability Assessment rates this vulnerability 'Exploitation More Likely' for both latest and older software releases — prioritize detection on Windows 7–11 and Windows Server 2008–2022 RDP client processes. ↗
- →The attack vector is server-to-client: a rogue RDP server triggers RCE on the connecting RDP client machine. Alert on RDP client processes (mstsc.exe, msrdc.exe) making outbound connections to non-corporate RDP endpoints. ↗
- →This vulnerability can be leveraged for lateral movement; monitor for unusual RDP client connections originating from internal hosts to other internal or external RDP servers. ↗
- ·The Talos Snort rules (58519, 58520, 58539–58541, Snort 3 rule 300054) cover exploitation attempts for multiple November 2021 Patch Tuesday CVEs collectively, not exclusively CVE-2021-38666. ↗
- ·Exploitation requires the victim to actively connect to an attacker-controlled RDP server, limiting opportunistic exploitation scenarios. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Remote Desktop Client Remote Code Execution Vulnerability
vendor_msrc·2021-11-09·CVSS 8.8
CVE-2021-38666 [HIGH] Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
In the case of a Remote Desktop connection, an attacker with control of a Remote Desktop Server could trigger a remote code execution (RCE) on the RDP client machine when a victim connects to the attacker's server with the vulnerable Remote Desktop Client.
Windows RDP: Windows RDP
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5007206
Reference: https://support.microsoft.com/help/5007206
Reference: https://catalog.update
GHSA
GHSA-vcc7-rh26-62x2: Remote Desktop Client Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-38666 [HIGH] GHSA-vcc7-rh26-62x2: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
Qualys
Microsoft & Adobe Patch Tuesday (November 2021) – Microsoft 55 Vulnerabilities with 6 Critical, 6 Zero-Days. Adobe 4 Vulnerabilities | Qualys
blogs_qualys·2021-11-11·CVSS 9.0
CVE-2021-42298 [CRITICAL] Microsoft & Adobe Patch Tuesday (November 2021) – Microsoft 55 Vulnerabilities with 6 Critical, 6 Zero-Days. Adobe 4 Vulnerabilities | Qualys
#### Table of Contents
- Microsoft Patch Tuesday November 2021
- Adobe Patch Tuesday October 2021
- Discover Patch Tuesday Vulnerabilities in VMDR
- Respond by Patching
- Patch Tuesday Dashboard
- About Patch Tuesday
## Microsoft Patch Tuesday – November 2021
Microsoft patched 55 vulnerabilities in their November 2021 Patch Tuesday release, of which six are rated as critical severity and six were previously reported as zero-days.
### Critical Microsoft Vulnerabilities Patched
CVE-2021-42298 – Microsoft Defender Remote Code Execution Vulnerability
This vulnerability in Microsoft Defender can be exploited using Maliciously crafted files. The remote code execution vulnerability will be triggered when the malicious file is opened by a user or scanned automatically via an outdated version
Qualys
Microsoft & Adobe Patch Tuesday (November 2021) – Microsoft 55 Vulnerabilities with 6 Critical, 6 Zero-Days. Adobe 4 Vulnerabilities
blogs_qualys·2021-11-11·CVSS 9.0
CVE-2021-42298 [CRITICAL] Microsoft & Adobe Patch Tuesday (November 2021) – Microsoft 55 Vulnerabilities with 6 Critical, 6 Zero-Days. Adobe 4 Vulnerabilities
## Table of Contents
Microsoft Patch Tuesday November 2021
Adobe Patch Tuesday October 2021
Discover Patch Tuesday Vulnerabilities in VMDR
Respond by Patching
Patch Tuesday Dashboard
About Patch Tuesday
## Microsoft Patch Tuesday – November 2021
Microsoft patched 55 vulnerabilities in their November 2021 Patch Tuesday release, of which six are rated as critical severity and six were previously reported as zero-days.
## Critical Microsoft Vulnerabilities Patched
CVE-2021-42298 – Microsoft Defender Remote Code Execution Vulnerability
This vulnerability in Microsoft Defender can be exploited using Maliciously crafted files. The remote code execution vulnerability will be triggered when the malicious file is opened by a user or scanned automatically via an outdated version of Micros
Trendmicro
November Continues Streak of Quiet Patch Tuesdays
blogs_trendmicro·2021-11-10·CVSS 9.0
[CRITICAL] November Continues Streak of Quiet Patch Tuesdays
Ausnutzung von Schwachstellen
## November Continues Streak of Quiet Patch Tuesdays
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.
By: Trend Micro Nov 10, 2021 Read time: ( words)
Save to Folio
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November (less than half of the vulnerabilities in November last year). Of these 55, four were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: Defender, Remote Desktop
Two Critical vulne
Trendmicro
November Continues Streak of Quiet Patch Tuesdays
blogs_trendmicro·2021-11-10·CVSS 9.0
[CRITICAL] November Continues Streak of Quiet Patch Tuesdays
Exploits y vulnerabilidades
## November Continues Streak of Quiet Patch Tuesdays
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.
By: Trend Micro Nov 10, 2021 Read time: ( words)
Save to Folio
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November (less than half of the vulnerabilities in November last year). Of these 55, four were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: Defender, Remote Desktop
Two Critical vulnera
Trendmicro
November Continues Streak of Quiet Patch Tuesdays
blogs_trendmicro·2021-11-10·CVSS 9.0
[CRITICAL] November Continues Streak of Quiet Patch Tuesdays
Exploits & Vulnerabilities
## November Continues Streak of Quiet Patch Tuesdays
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.
By: Trend Micro Nov 10, 2021 Read time: ( words)
Save to Folio
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November (less than half of the vulnerabilities in November last year). Of these 55, four were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: Defender, Remote Desktop
Two Critical vulnerab
Trendmicro
November Continues Streak of Quiet Patch Tuesdays
blogs_trendmicro·2021-11-10·CVSS 9.0
[CRITICAL] November Continues Streak of Quiet Patch Tuesdays
Exploits & Vulnerabilities
## November Continues Streak of Quiet Patch Tuesdays
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.
By: Trend Micro 2021/11/10 Read time: ( words)
Save to Folio
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November (less than half of the vulnerabilities in November last year). Of these 55, four were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: Defender, Remote Desktop
Two Critical vulnerabil
Trendmicro
November Continues Streak of Quiet Patch Tuesdays
blogs_trendmicro·2021-11-10·CVSS 9.0
[CRITICAL] November Continues Streak of Quiet Patch Tuesdays
Exploits & Vulnerabilities
# November Continues Streak of Quiet Patch Tuesdays
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.
By: Trend Micro
2021/11/10
Read time: ( words)
Save to Folio
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November (less than half of the vulnerabilities in November last year). Of these 55, four were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: Defender, Remote Desktop
Two Critical vulnerabil
Trendmicro
November Continues Streak of Quiet Patch Tuesdays
blogs_trendmicro·2021-11-10·CVSS 9.0
[CRITICAL] November Continues Streak of Quiet Patch Tuesdays
Sfruttamento vulnerabilità
## November Continues Streak of Quiet Patch Tuesdays
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.
By: Trend Micro Nov 10, 2021 Read time: ( words)
Save to Folio
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November (less than half of the vulnerabilities in November last year). Of these 55, four were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: Defender, Remote Desktop
Two Critical vulnerab
Talos
Microsoft Patch Tuesday for Nov. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-11-09·CVSS 8.8
CVE-2021-42292 [HIGH] Microsoft Patch Tuesday for Nov. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw and Tiago Pereira.
Microsoft released its monthly security update Tuesday, disclosing 56 vulnerabilities in the company’s various software, hardware and firmware offerings, including one that’s actively being exploited in the wild.
November’s security update features six critical vulnerabilities, up from last month’s two, which was far lower than average for Microsoft. The other 50 vulnerabilities fixed today are considered “important.”
CVE-2021-42292 is one of those vulnerabilities considered “important” and not critical, though it is the only one included in this security update that Microsoft reports has been spotted being exploited in the wild. An attacker could exploit this vulnerability in Microsoft Excel to bypass certain security settings on targeted machines.
In
Talos
Microsoft Patch Tuesday for Nov. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-11-09·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for Nov. 2021 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for Nov. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw and Tiago Pereira.
Microsoft released its monthly security update Tuesday, disclosing 56 vulnerabilities in the company’s various software, hardware and firmware offerings, including one that’s actively being exploited in the wild.
November’s security update features six critical vulnerabilities, up from last month’s two, which was far lower than average for Microsoft. The other 50 vulnerabilities fixed today are considered “important.”
CVE-2021-42292 is one of those vulnerabilities considered “important” and not critical, though it is the only one included in this security update that Microsoft reports has been spotted being exploited in the wild. An attacker could exploit this vulnerab
Krebs
Microsoft Patch Tuesday, November 2021 Edition
blogs_krebs·2021-11-09·CVSS 4.4
CVE-2021-42292 [MEDIUM] Microsoft Patch Tuesday, November 2021 Edition
Microsoft Corp. today released updates to quash at least 55 security bugs in its Windows operating systems and other software. Two of the patches address vulnerabilities that are already being used in active attacks online, and four of the flaws were disclosed publicly before today — potentially giving adversaries a head start in figuring out how to exploit them.
Among the zero-day bugs is CVE-2021-42292, a “security feature bypass” problem with Microsoft Excel versions 2013-2021 that could allow attackers to install malicious code just by convincing someone to open a booby-trapped Excel file (Microsoft says Mac versions of Office are also affected, but several places are reporting that Office for Mac security updates aren’t available yet).
Microsoft’s revised, more sparse security advis
Krebs
Microsoft Patch Tuesday, November 2021 Edition
blogs_krebs·2021-11-09·CVSS 4.4
CVE-2021-42292 [MEDIUM] Microsoft Patch Tuesday, November 2021 Edition
Microsoft Corp. today released updates to quash at least 55 security bugs in its Windows operating systems and other software. Two of the patches address vulnerabilities that are already being used in active attacks online, and four of the flaws were disclosed publicly before today — potentially giving adversaries a head start in figuring out how to exploit them.
Among the zero-day bugs is CVE-2021-42292 , a “security feature bypass” problem with Microsoft Excel versions 2013-2021 that could allow attackers to install malicious code just by convincing someone to open a booby-trapped Excel file (Microsoft says Mac versions of Office are also affected, but several places are reporting that Office for Mac security updates aren’t available yet).
Microsoft’s revised, more sparse security advi
Tenable
Microsoft’s November 2021 Patch Tuesday Addresses 55 CVEs (CVE-2021-42321)
blogs_tenable·2021-11-09·CVSS 8.8
[HIGH] Microsoft’s November 2021 Patch Tuesday Addresses 55 CVEs (CVE-2021-42321)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Crowdstrike
November 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] November 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
November 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] November 2021 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Zscaler
Zscaler found Windows Security Vulnerabilities | 11-09-2021
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler found Windows Security Vulnerabilities | 11-09-2021
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2021-11-10
Published