PT-2021-2637 · Microsoft · Windows Wlan Autoconfig Service+1

Matthew Johnson

·

Published

2021-04-13

·

Updated

2023-12-29

·

CVE-2021-28316

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Windows WLAN AutoConfig Service versions prior to the fixed version
Description: The issue is related to errors in security settings of the Windows WLAN service, allowing an attacker to gain unauthorized access to protected information. This security-feature bypass vulnerability affects the system. The Airstrike Attack allows for FDE bypass and EoP on domain-joined Windows workstations.
Recommendations: For Windows WLAN AutoConfig Service versions prior to the fixed version, update to the latest version to resolve the issue. As a temporary workaround, consider restricting access to the WLAN AutoConfig Service to minimize the risk of exploitation. Avoid using vulnerable configurations in the WLAN service until the issue is resolved.

Fix

Weakness Enumeration

Related Identifiers

BDU:2021-02155
CVE-2021-28316

Affected Products

Windows
Windows Wlan Autoconfig Service