7.8

CVE-2021-43226

Warnung

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftWindows 10 1507 HwPlatformx64 Version < 10.0.10240.19145
MicrosoftWindows 10 1507 HwPlatformx86 Version < 10.0.10240.19145
MicrosoftWindows 10 1607 HwPlatformx64 Version < 10.0.14393.4825
MicrosoftWindows 10 1607 HwPlatformx86 Version < 10.0.14393.4825
MicrosoftWindows 10 1809 Version < 10.0.17763.2366
MicrosoftWindows 10 1909 Version < 10.0.18363.1977
MicrosoftWindows 10 2004 Version < 10.0.19041.1415
MicrosoftWindows 10 20h2 HwPlatformarm64 Version < 10.0.19042.1415
MicrosoftWindows 10 20h2 HwPlatformx86 Version < 10.0.19042.1415
MicrosoftWindows 10 21h1 Version < 10.0.19043.1415
MicrosoftWindows 10 21h2 Version < 10.0.19044.1415
MicrosoftWindows 11 21h2 Version < 10.0.22000.376
MicrosoftWindows 7 Version- Updatesp1
MicrosoftWindows 8.1 Version-
MicrosoftWindows Rt 8.1 Version-
MicrosoftWindows Server 2004 Version < 10.0.19041.1415
MicrosoftWindows Server 2008 Version- Updatesp2 HwPlatformx64
MicrosoftWindows Server 2008 Version- Updatesp2 HwPlatformx86
MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
MicrosoftWindows Server 2016 Version < 10.0.14393.4825
MicrosoftWindows Server 2019 Version < 10.0.17763.2366
MicrosoftWindows Server 2022 Version < 10.0.20348.405
MicrosoftWindows Server 20h2 Version < 10.0.19042.1415

06.10.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Windows Privilege Escalation Vulnerability

Schwachstelle

Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 38% 0.971
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
secure@microsoft.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H