7.8

CVE-2021-1651

Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability

Data is provided by the National Vulnerability Database (NVD)
MicrosoftVisual Studio Version2015 Updateupdate3
MicrosoftVisual Studio 2017 Version >= 15.0 < 15.9
MicrosoftVisual Studio 2019 Version >= 16.0 < 16.4
MicrosoftVisual Studio 2019 Version >= 16.5 < 16.7
MicrosoftVisual Studio 2019 Version16.8
MicrosoftWindows 10 Version20h2
MicrosoftWindows 10 Version1607
MicrosoftWindows 10 Version1803
MicrosoftWindows 10 Version1809
MicrosoftWindows 10 Version1909
MicrosoftWindows 10 Version2004
MicrosoftWindows Server 2016 Version20h2
MicrosoftWindows Server 2016 Version1909
MicrosoftWindows Server 2016 Version2004
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.46% 0.632
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
secure@microsoft.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.