7.8

CVE-2021-1647

Warning

Microsoft Defender Remote Code Execution Vulnerability

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows Defender Version-
   MicrosoftWindows 10 1507 Version-
   MicrosoftWindows 10 1607 Version-
   MicrosoftWindows 10 1803 Version-
   MicrosoftWindows 10 1809 Version-
   MicrosoftWindows 10 1909 Version-
   MicrosoftWindows 10 2004 Version-
   MicrosoftWindows 10 20h2 Version-
   MicrosoftWindows 7 Version- Updatesp1
   MicrosoftWindows 8.1 Version-
   MicrosoftWindows Rt 8.1 Version-
   MicrosoftWindows Server 1909 Version-
   MicrosoftWindows Server 2004 Version-
   MicrosoftWindows Server 2008 Version- Updatesp2
   MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
   MicrosoftWindows Server 2012 Version-
   MicrosoftWindows Server 2012 Versionr2
   MicrosoftWindows Server 2016 Version-
   MicrosoftWindows Server 2019 Version-
   MicrosoftWindows Server 20h2 Version-
MicrosoftSystem Center Endpoint Protection Version2012 Updater2

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Defender Remote Code Execution Vulnerability

Vulnerability

Microsoft Defender contains an unspecified vulnerability that allows for remote code execution.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 73.81% 0.988
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
secure@microsoft.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H