cbcvebase.
CVE-2021-42278
published 2021-11-10

CVE-2021-42278: Active Directory Domain Services Elevation of Privilege Vulnerability

PriorityP189high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-02
Exploited in the wild
EPSS
70.21%
99.3th percentile
Active Directory Domain Services Elevation of Privilege Vulnerability

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_server_2004< 10.0.19041.134810.0.19041.1348
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.0.0 < 6.1.7601.257696.1.7601.25769
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.0 < 6.1.7601.257696.1.7601.25769
microsoftwindows_server_2008_service_pack_2>= 6.0.0 < 6.0.6003.212826.0.6003.21282
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.0 < 6.2.9200.235176.2.9200.23517
microsoftwindows_server_2012_r2>= 6.3.0 < 6.3.9600.201746.3.9600.20174
microsoftwindows_server_2016< 10.0.14393.477010.0.14393.4770
microsoftwindows_server_2016>= 10.0.0 < 10.0.14393.477010.0.14393.4770
microsoftwindows_server_2019< 10.0.17763.230010.0.17763.2300
microsoftwindows_server_2019>= 10.0.0 < 10.0.17763.230010.0.17763.2300
microsoftwindows_server_2022< 10.0.20348.35010.0.20348.350
microsoftwindows_server_2022>= 10.0.0 < 10.0.20348.35010.0.20348.350
microsoftwindows_server_20h2< 10.0.19042.134810.0.19042.1348
microsoftwindows_server_version_2004>= 10.0.0 < 10.0.19041.134810.0.19041.1348
microsoftwindows_server_version_20h2>= 10.0.0 < 10.0.19042.134810.0.19042.1348
msrcwindows_server_2008_for_32-bit_systems_service_pack_2
msrcwindows_server_2008_for_x64-based_systems_service_pack_2
msrcwindows_server_2008_r2_for_x64-based_systems_service_pack_1
msrcwindows_server_2012
msrcwindows_server_2012_r2
msrcwindows_server_2016
msrcwindows_server_2019
msrcwindows_server_2022

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://github.com/WazeHell/sam-the-admin
otherMS.Active.Directory.SAM.Privilege.Escalation
ip45.67.229.148
path\Windows\ILUg69ql1.bat
path\Windows\ILUg69ql2.bat
path\Windows\ILUg69ql3.bat
commandpowershell -ExecutionPolicy Bypass -command "New-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender' -Name DisableAntiSpyware -Value 1 -PropertyType DWORD -Force"
commandpowershell -ExecutionPolicy Bypass -command "Set-MpPreference -DisableRealtimeMonitoring 1"
commandpowershell -ExecutionPolicy Bypass Uninstall-WindowsFeature -Name Windows-Defender
commandcmd /C C:\intel\AF.exe -f objectcategory=computer -csv name cn OperatingSystem dNSHostName > C:\intel\[REDACTED].csv
registryHKLM:\SOFTWARE\Policies\Microsoft\Windows Defender
filenameWindefCheck.exe
filenameAF.exe
  • Monitor MachineAccountQuota usage: unprivileged users creating computer accounts is a prerequisite for NoPac exploitation. Alert on non-admin users creating computer accounts, especially when followed by SPN/sAMAccountName modifications.
  • Black Basta operators use a batch script naming convention 'ILUg69ql' followed by a digit (e.g., ILUg69ql1.bat, ILUg69ql2.bat, ILUg69ql3.bat) dropped into the Windows directory to disable Defender. Hunt for this pattern in Windows event logs and EDR telemetry.
  • Detect NoPac/spider.dll usage alongside zero.exe in privilege escalation attempts exploiting CVE-2021-42278 and CVE-2021-42287 in Black Basta intrusions.
  • Conti ransomware operators were observed making many attempts to exploit CVE-2021-42278 and CVE-2021-42287 to create privileged accounts. Monitor AD for anomalous computer account creation and sAMAccountName changes in conjunction with Conti TTPs.
  • FortiGuard IPS signature 'MS.Active.Directory.SAM.Privilege.Escalation' detects and blocks CVE-2021-42278/CVE-2021-42287 exploitation attempts at the network level (IPS DB 19.228).
  • ·CVE-2021-42278 is only exploitable under default AD configuration where MachineAccountQuota allows unprivileged users to create computer accounts. Reducing MachineAccountQuota to 0 mitigates the primary attack vector.
  • ·Microsoft patches KB5008380 and KB5008602 must both be applied to fully remediate the CVE-2021-42278/CVE-2021-42287 combined attack chain.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vulncheck7.5HIGH
cisa7.5HIGH
vendor_msrc7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.