PT-2021-2637 · Microsoft · Windows Wlan Autoconfig Service+1
Matthew Johnson
·
Published
2021-04-13
·
Updated
2023-12-29
·
CVE-2021-28316
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Windows WLAN AutoConfig Service versions prior to the fixed version
Description:
The issue is related to errors in security settings of the Windows WLAN service, allowing an attacker to gain unauthorized access to protected information. This security-feature bypass vulnerability affects the system. The Airstrike Attack allows for FDE bypass and EoP on domain-joined Windows workstations.
Recommendations:
For Windows WLAN AutoConfig Service versions prior to the fixed version, update to the latest version to resolve the issue. As a temporary workaround, consider restricting access to the WLAN AutoConfig Service to minimize the risk of exploitation. Avoid using vulnerable configurations in the WLAN service until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Wlan Autoconfig Service