7.8
CVE-2021-42286
- EPSS 0.25%
- Veröffentlicht 10.11.2021 01:19:45
- Zuletzt bearbeitet 21.11.2024 06:27:31
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 Version20h2 HwPlatformarm64
Microsoft ≫ Windows 10 Version20h2 HwPlatformx64
Microsoft ≫ Windows 10 Version20h2 HwPlatformx86
Microsoft ≫ Windows 10 Version21h1 HwPlatformarm64
Microsoft ≫ Windows 10 Version21h1 HwPlatformx64
Microsoft ≫ Windows 10 Version21h1 HwPlatformx86
Microsoft ≫ Windows 10 Version2004 HwPlatformarm64
Microsoft ≫ Windows 10 Version2004 HwPlatformx64
Microsoft ≫ Windows 10 Version2004 HwPlatformx86
Microsoft ≫ Windows Server Version20h2
Microsoft ≫ Windows Server 2016 Version2004
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.481 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| secure@microsoft.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.