PT-2021-3785 · Microsoft · Windows

Harmj0Y

+3

·

Published

2021-08-10

·

Updated

2026-03-19

·

CVE-2021-36942

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows Local Security Authority (LSA) versions are affected, but specific versions are not provided in the input data.
Description A spoofing issue allows attackers to affect the system. The problem is related to the Local Security Authority (LSA) in Windows. Details about real-world incidents where this issue was exploited are not provided. Technical details about exploitation include the use of EfsRpcEncryptFileSrv to bypass the latest MS patch. The issue can be exploited through RPC, and a named pipe, such as "lsarpc", can be used. The estimated number of potentially affected devices worldwide is not available.
Recommendations No specific recommendations for resolving the issue are provided in the input data for each affected version.

Exploit

Fix

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

BDU:2021-04045
CVE-2021-36942
MICROSOFTWINDOWSCVE2021_36942

Affected Products

Windows