PT-2021-4805 · Microsoft · Windows Server+2

Andrew Bartlett

·

Published

2021-11-09

·

Updated

2026-03-10

·

CVE-2021-42278

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows Server versions prior to the fixed version Microsoft Active Directory Domain Services (affected versions not specified)
Description The issue is related to insecure privilege management in Active Directory Domain Services, allowing a remote attacker to elevate privileges in the system. This is an elevation-of-privilege vulnerability that can affect the system.
Recommendations For Microsoft Windows Server versions prior to the fixed version, update to the latest version to resolve the issue. For Microsoft Active Directory Domain Services, consider restricting access to sensitive areas of the system until a patch is available. As a temporary workaround, consider disabling any features that rely on privilege escalation until a patch is available.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2021-05532
CVE-2021-42278

Affected Products

Active Directory Domain Services
Windows Server
Windows