CVE-2021-42286

Severity
7.8HIGH
EPSS
0.2%
top 51.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateMay 24

Description

Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages8 packages

CVEListV5microsoft/windows_10_version_200410.0.010.0.19041.1348
CVEListV5microsoft/windows_10_version_20h210.0.010.0.19042.1348
CVEListV5microsoft/windows_10_version_21h110.0.010.0.19043.1348
CVEListV5microsoft/windows_server_version_200410.0.010.0.19041.1348
CVEListV5microsoft/windows_server_version_20h210.0.010.0.19041.1348

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gpw2-42fw-wq8h: Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability2022-05-24
CVEList
Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability2021-11-10

📋Vendor Advisories

1
Microsoft
Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability2021-11-09
CVE-2021-42286 (HIGH CVSS 7.8) | Windows Core Shell SI Host Extensio | cvebase.io