PT-2021-2045 · Microsoft · Windows

Published

2021-02-09

·

Updated

2024-08-29

·

CVE-2021-24086

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Windows versions prior to the fixed version
Description: The issue is related to a Denial of Service vulnerability in the Windows TCP/IP service, which can be exploited to cause a system crash. It is also associated with errors in privilege management in the Windows Event Tracing service. The vulnerability can be exploited by an attacker to cause a denial of service. There is no information about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations: For Windows versions prior to the fixed version, update to the latest version to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable tcpip.sys module to minimize the risk of exploitation.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2021-00892
CVE-2021-24086

Affected Products

Windows