CVE-2021-43217
published 2021-12-15CVE-2021-43217: Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.42%
92.9th percentile
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.0 < 10.0.10240.19145 | 10.0.10240.19145 |
| microsoft | windows_10_version_1607 | >= 10.0.0 < 10.0.14393.4825 | 10.0.14393.4825 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2366 | 10.0.17763.2366 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.1977 | 10.0.18363.1977 |
| microsoft | windows_10_version_2004 | >= 10.0.0 < 10.0.19041.1415 | 10.0.19041.1415 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1415 | 10.0.19042.1415 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1415 | 10.0.19043.1415 |
| microsoft | windows_10_version_21h2 | >= 10.0.0 < 10.0.19044.1415 | 10.0.19044.1415 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.376 | 10.0.22000.376 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25796 | 6.1.7601.25796 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25796 | 6.1.7601.25796 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20207 | 6.3.9600.20207 |
| microsoft | windows_server | — | — |
| microsoft | windows_server | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < 6.1.7601.25796 | 6.1.7601.25796 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < 6.1.7601.25796 | 6.1.7601.25796 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < 6.0.6003.21309 | 6.0.6003.21309 |
| microsoft | windows_server_2012 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect EFS client connections that lack packet-level privacy — CVE-2021-43217 exploits the absence of packet-level privacy on EFS connections to trigger a buffer overflow write leading to unauthenticated non-sandboxed code execution. ↗
- →Audit the presence of the AllowAllCliAuth registry key — its existence may indicate a weakened EFS server configuration susceptible to exploitation; it is removed in the enforcement phase. ↗
- ·The two-phase rollout means unpatched or partially patched environments (only client or only server updated) remain at risk; Microsoft recommends patching client machines first, then servers. ↗
- ·During the initial phase (December 14, 2021 updates), the AllowAllCliAuth registry key can still be used to allow non-packet-level-privacy connections on servers, leaving a configuration gap until the Q1 2022 enforcement phase. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
vendor_msrc·2021-12-14·CVSS 8.1
CVE-2021-43217 [HIGH] Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
FAQ: What is the attack vector for this vulnerability?
An attacker could cause a buffer overflow write leading to unauthenticated non-sandboxed code execution.
Does EFS need to be in use for this to be exploited?
No. EFS interfaces trigger a start to the EFS service if it isn’t already running.
How does Microsoft plan to address this vulnerability?
Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how EFS makes connections from client to server.
For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see KB5009763: EFS security hardening changes in CVE-2021-43217.
When the second
GHSA
GHSA-q33m-rrqm-6xhw: Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
ghsa_unreviewed·2021-12-16
CVE-2021-43217 [CRITICAL] CWE-94 GHSA-q33m-rrqm-6xhw: Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
Qualys
Microsoft & Adobe Patch Tuesday (December 2021) – Microsoft 83 Vulnerabilities With 7 Critical, 1 Actively Exploited. Adobe 60 Vulnerabilities, 28 Critical.
blogs_qualys·2021-12-14·CVSS 9.8
[CRITICAL] Microsoft & Adobe Patch Tuesday (December 2021) – Microsoft 83 Vulnerabilities With 7 Critical, 1 Actively Exploited. Adobe 60 Vulnerabilities, 28 Critical.
## Table of Contents
Microsoft Patch Tuesday December 2021
Microsoft Vulnerabilities To Be Prioritized and Patched Quickly.
Adobe Patch Tuesday December 2021
Discover and Prioritize Patch Tuesday Vulnerabilities in VMDR
Respond by Patching
Patch Tuesday Dashboard
Webinar Series: This Month in Vulnerabilities and Patches
About Patch Tuesday
Contributor
## Microsoft Patch Tuesday – December 2021
Microsoft patched 83 vulnerabilities in their December 2021 Patch Tuesday release, of which seven are rated as critical severity. This month’s release includes one Zero Day known to be actively exploited.
Products impacted by Microsoft’s December security update include Microsoft Office, Microsoft PowerShell, the Chromium-based Edge browser, the Windows Kernel, Print Spooler, and Remote D
Qualys
Microsoft & Adobe Patch Tuesday (December 2021) – Microsoft 83 Vulnerabilities With 7 Critical, 1 Actively Exploited. Adobe 60 Vulnerabilities, 28 Critical. | Qualys
blogs_qualys·2021-12-14·CVSS 9.8
[CRITICAL] Microsoft & Adobe Patch Tuesday (December 2021) – Microsoft 83 Vulnerabilities With 7 Critical, 1 Actively Exploited. Adobe 60 Vulnerabilities, 28 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday December 2021
- Microsoft Vulnerabilities To Be Prioritized and Patched Quickly.
- Adobe Patch Tuesday December 2021
- Discover and Prioritize Patch Tuesday Vulnerabilities in VMDR
- Respond by Patching
- Patch Tuesday Dashboard
- Webinar Series: This Month in Vulnerabilities and Patches
- About Patch Tuesday
- Contributor
## Microsoft Patch Tuesday – December 2021
Microsoft patched 83 vulnerabilities in their December 2021 Patch Tuesday release, of which seven are rated as critical severity. This month’s release includes one Zero Day known to be actively exploited.
Products impacted by Microsoft’s December security update include Microsoft Office, Microsoft PowerShell, the Chromium-based Edge browser, the Windows Kernel, Print Spooler,
2021-12-15
Published