PT-2021-3785 · Microsoft · Windows
Harmj0Y
+3
·
Published
2021-08-10
·
Updated
2026-03-19
·
CVE-2021-36942
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Local Security Authority (LSA) versions are affected, but specific versions are not provided in the input data.
Description
A spoofing issue allows attackers to affect the system. The problem is related to the Local Security Authority (LSA) in Windows. Details about real-world incidents where this issue was exploited are not provided. Technical details about exploitation include the use of
EfsRpcEncryptFileSrv to bypass the latest MS patch. The issue can be exploited through RPC, and a named pipe, such as "lsarpc", can be used. The estimated number of potentially affected devices worldwide is not available.Recommendations
No specific recommendations for resolving the issue are provided in the input data for each affected version.
Exploit
Fix
UI Misrepresentation of Critical Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows