⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2021-43207

Severity
7.8HIGH
EPSS
0.3%
top 45.10%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedDec 15
Latest updateDec 16

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages30 packages

CVEListV5microsoft/windows_76.1.06.1.7601.25796
CVEListV5microsoft/windows_8.16.3.06.3.9600.20207
CVEListV5microsoft/windows_server_20126.2.06.2.9200.23545+1
CVEListV5microsoft/windows_server_201610.0.010.0.14393.4825
CVEListV5microsoft/windows_server_201910.0.010.0.17763.2366

Patches

🔴Vulnerability Details

3
GHSA
GHSA-w3v4-69ph-pfjp: Windows Common Log File System Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-432262021-12-16
CVEList
Windows Common Log File System Driver Elevation of Privilege Vulnerability2021-12-15
VulnCheck
Windows Common Log File System Driver Elevation of Privilege Vulnerability2021

📋Vendor Advisories

1
Microsoft
Windows Common Log File System Driver Elevation of Privilege Vulnerability2021-12-14
CVE-2021-43207 (HIGH CVSS 7.8) | Windows Common Log File System Driv | cvebase.io