CVE-2021-42298

CWE-94Code Injection7 documents6 sources
Severity
7.8HIGH
EPSS
2.3%
top 15.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateMay 24

Description

Microsoft Defender Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5microsoft/microsoft_malware_protection_engine1.1.0.01.1.18700.3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hrr5-6mf9-3wxh: Microsoft Defender Remote Code Execution Vulnerability2022-05-24
CVEList
Microsoft Defender Remote Code Execution Vulnerability2021-11-10
VulnCheck
Microsoft Malware Protection Engine Improper Control of Generation of Code ('Code Injection')2021

📋Vendor Advisories

1
Microsoft
Microsoft Defender Remote Code Execution Vulnerability2021-11-09

🕵️Threat Intelligence

2
Qualys
Microsoft & Adobe Patch Tuesday (November 2021) – Microsoft 55 Vulnerabilities with 6 Critical, 6 Zero-Days. Adobe 4 Vulnerabilities | Qualys2021-11-11
Qualys
Microsoft & Adobe Patch Tuesday (November 2021) – Microsoft 55 Vulnerabilities with 6 Critical, 6 Zero-Days. Adobe 4 Vulnerabilities2021-11-11
CVE-2021-42298 (HIGH CVSS 7.8) | Microsoft Defender Remote Code Exec | cvebase.io