7.2
CVE-2021-41345
- EPSS 0.83%
- Veröffentlicht 13.10.2021 01:15:13
- Zuletzt bearbeitet 21.11.2024 06:26:06
- Erkennungen
Storage Spaces Controller Elevation of Privilege Vulnerability
Storage Spaces Controller Elevation of Privilege Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 Version -
Microsoft ≫ Windows 10 Version 20h2
Microsoft ≫ Windows 10 Version 21h1
Microsoft ≫ Windows 10 Version 1607
Microsoft ≫ Windows 10 Version 1809
Microsoft ≫ Windows 10 Version 1909
Microsoft ≫ Windows 10 Version 2004
Microsoft ≫ Windows 11 Version - HwPlatform arm64
Microsoft ≫ Windows 11 Version - HwPlatform x64
Microsoft ≫ Windows 8.1 Version - SwEdition - HwPlatform -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows Server 2016 Version -
Microsoft ≫ Windows Server 2016 Version 20h2
Microsoft ≫ Windows Server 2016 Version 2004
Microsoft ≫ Windows Server 2019 Version -
Microsoft ≫ Windows Server 2022 Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.83% | 0.54 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| Microsoft | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-190 Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41345
https://www.zerodayinitiative.com/advisories/ZDI-21-1154/