CVE-2021-42291Improper Privilege Management in Microsoft Windows Server 2008 R2 Service Pack 1

Severity
8.8HIGHNVD
CNA7.5
EPSS
1.2%
top 20.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateMay 24

Description

Active Directory Domain Services Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages11 packages

CVEListV5microsoft/windows_server_20126.2.06.2.9200.23517
CVEListV5microsoft/windows_server_201610.0.010.0.14393.4770
CVEListV5microsoft/windows_server_201910.0.010.0.17763.2300
CVEListV5microsoft/windows_server_202210.0.010.0.20348.350
CVEListV5microsoft/windows_server_2012_r26.3.06.3.9600.20174

Patches

🔴Vulnerability Details

2
GHSA
GHSA-ffqv-33xf-m57q: Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-422872022-05-24
CVEList
Active Directory Domain Services Elevation of Privilege Vulnerability2021-11-10

📋Vendor Advisories

1
Microsoft
Active Directory Domain Services Elevation of Privilege Vulnerability2021-11-09
CVE-2021-42291 — Improper Privilege Management | cvebase