VDB
BDU%3A2021-05532
BDU%3A2021-05532
PUBLISHED
CVSS 9 CRITICAL
Уязвимость службы Active Directory операционных систем Windows, связанная с небезопасным управлением привилегиями, позволяющая нарушителю повысить привилегии в системе
Risk Scores
CVSS 2.0
9
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp | Windows Server 2008 Service Pack 2, Windows Server 2012, Windows Server 2012 R2, Windows Server 2008 R2 Service Pack 1, Windows Server 2016, Windows Server 2008 Service Pack 2 (Server Core Installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2008 R2 Service Pack 2 (Server Core installation), Windows Server 2004 (Server Core Installation), Windows Server 20H2 (Server Core Installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2012 (Server Core installation) |
Timeline
- Nov 18, 2021 CVE Published
- Nov 29, 2024 PoC Published
- Apr 23, 2025 CVE Updated
- Mar 19, 2026 Security Advisory
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278 url
- https://nvd.nist.gov/vuln/detail/CVE-2021-42278 url
- https://www.cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv url
- https://content.kaspersky-labs.com/fm/site-editor/18/18b11446b26bf9d75192859778e9a9de/source/report-ir2024.pdf url