VDB

CVE-2021-36948

CVE-2021-36948 PUBLISHED KEV CVSS 7.800000190734863 HIGH

Windows User Profile Service Elevation of Privilege Vulnerability

EPSS 1.05% · 77.9th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
1.05%
77.9th percentile

Affected Products

VendorProductVersions
MicrosoftWindows 10 Version 21H110.0.0
MicrosoftWindows Server 2008 R2 Service Pack 16.1.0
MicrosoftWindows Server 201610.0.0
MicrosoftWindows 7 Service Pack 16.1.0
MicrosoftWindows Server version 20H210.0.0
MicrosoftWindows Server 2012 (Server Core installation)6.2.0
MicrosoftWindows Server version 200410.0.0
MicrosoftWindows Server 2008 R2 Service Pack 1 (Server Core installation)6.0.0
MicrosoftWindows Server 2012 R2 (Server Core installation)6.3.0
MicrosoftWindows Server 2008 Service Pack 26.0.0
MicrosoftWindows Server 2016 (Server Core installation)10.0.0
MicrosoftWindows Server 201910.0.0
MicrosoftWindows 10 Version 20H210.0.0
MicrosoftWindows 10 Version 180910.0.0
MicrosoftWindows 10 Version 160710.0.0
MicrosoftWindows Server 20126.2.0
MicrosoftWindows 10 Version 150710.0.0
MicrosoftWindows Server 2012 R26.3.0
MicrosoftWindows Server 2008 Service Pack 2 (Server Core installation)6.0.0
MicrosoftWindows 8.16.3.0

…and 5 more

Timeline

  • Aug 11, 2021 CVE Published
  • Aug 11, 2021 PoC Published
  • Aug 13, 2021 EPSS Score
  • Aug 21, 2021 EPSS Score
  • Oct 11, 2021 EPSS Score
  • Nov 3, 2021 CISA KEV Added
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 5, 2022 EPSS Score
  • Apr 4, 2022 EPSS Score
  • Jul 31, 2022 EPSS Score
  • Sep 28, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›