CVE-2021-41337
published 2021-10-13CVE-2021-41337: Active Directory Security Feature Bypass Vulnerability
medium4.9CVSS 3.1
AVNACLPRHUINSUCNIHAN
Active Directory Security Feature Bypass Vulnerability
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | >= 10.0.0 < 10.0.14393.4704 | 10.0.14393.4704 |
| microsoft | windows_server_2019 | >= 10.0.0 < 10.0.17763.2237 | 10.0.17763.2237 |
| microsoft | windows_server_2022 | >= 10.0.0 < 10.0.20348.288 | 10.0.20348.288 |
| microsoft | windows_server_version_2004 | >= 10.0.0 < 10.0.19041.1288 | 10.0.19041.1288 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1288 | 10.0.19042.1288 |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_version_2004 | — | — |
| msrc | windows_server_version_20h2 | — | — |
Microsoft
Active Directory Security Feature Bypass Vulnerability
vendor_msrc·2021-10-12·CVSS 4.9
CVE-2021-41337 [MEDIUM] Active Directory Security Feature Bypass Vulnerability
Active Directory Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
This vulnerability could allow an attacker to bypass Active Directory domain permissions for Key Admins groups.
Role: Windows Active Directory Server: Role: Windows Active Directory Server
Microsoft: Microsoft
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5006672
Reference: https://support.microsoft.com/help/5006672
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5006699
Reference: https://catal
GHSA
GHSA-j35m-723v-8hgh: Active Directory Security Feature Bypass Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-41337 [MEDIUM] GHSA-j35m-723v-8hgh: Active Directory Security Feature Bypass Vulnerability
Active Directory Security Feature Bypass Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-13
Published