HIGH
CVE-2021-42278
CVSS
7.5
KEV
Description
Active Directory Domain Services Elevation of Privilege Vulnerability
Summary dbcve.org
This is an elevation of privilege vulnerability in Microsoft Active Directory Domain Services. It allows an authenticated attacker to gain elevated privileges within the domain, potentially compromising the entire Active Directory environment.
Mitigation
Apply the Microsoft security updates for CVE-2021-42278 and CVE-2021-42278. Ensure all domain controllers are patched and monitor for suspicious Kerberos ticket requests.
EPSS Score
73.3%
Probability of exploitation in next 30 days
99.4th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278
Patch, Vendor Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42278
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-42278
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.