PT-2020-5738 · Microsoft · Windows

Abdelhamid Naceri

+1

·

Published

2020-11-11

·

Updated

2023-12-29

·

CVE-2021-26889

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Windows (affected versions not specified)
Description: The issue is related to an elevation-of-privilege vulnerability in the Windows Update Stack, which is caused by insecure privilege management. This vulnerability can be exploited to allow an attacker to elevate their privileges or execute arbitrary code. The vulnerability affects the system and can be exploited by attackers.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Link Following

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2021-01676
CVE-2021-26889
ZDI-21-328

Affected Products

Windows