HIGH

CVE-2021-42278

Microsoft Windows Server 2004 2021-11-10 CVSS v3.1
CVSS
7.5
KEV

Description

Active Directory Domain Services Elevation of Privilege Vulnerability

Summary dbcve.org

This is an elevation of privilege vulnerability in Microsoft Active Directory Domain Services. It allows an authenticated attacker to gain elevated privileges within the domain, potentially compromising the entire Active Directory environment.

Mitigation

Apply the Microsoft security updates for CVE-2021-42278 and CVE-2021-42278. Ensure all domain controllers are patched and monitor for suspicious Kerberos ticket requests.

Patch Commit

EPSS Score

73.3%
Probability of exploitation in next 30 days
99.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE