Vulnerability · NVD
CVE-2021-26443
CVE-2021-26443 : critical severity (CVSS 9.0). No tracked catalog app is linked to this CVE.
- Severity (CVSS)
- 9.0
- Exploitation
- 1.7 %
- Tracked apps
- 0
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
Attack vector : Adjacent network
No user interaction
Show raw CVSS vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS
1.68%
above median
percentile 76.0%
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Server 2022 Fixed in 10.0.20348.350
- Windows Server 2019 Fixed in 10.0.17763.2300
- Windows 11 21H2 · 2021-H2 Fixed in 10.0.22000.318
- Windows 10 21H1 · 2021-H1 Fixed in 10.0.19043.1348
- Windows 10 2004 · 2020-04 Fixed in 10.0.19041.1348
- Windows 10 1909 · 2019-09 Fixed in 10.0.18363.1916
- Windows 10 1809 · 2018-09 Fixed in 10.0.17763.2300
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.