KEV · Actively exploited
CVE-2021-42287
HIGH 7.5
KEV
Active Directory Domain Services Elevation of Privilege Vulnerability
EPSS
94.01%
exploit likely
percentile 99.9%
CISA Known Exploited Vulnerability
- Added to KEV
- 2022-04-11
- Remediation deadline
- 2022-05-02
- Required action
- Apply updates per vendor instructions.
- Ransomware
- Yes, known ransomware campaign
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Fixed in Windows Server 2022 (Server Core installation) 10.0.20348.350 Windows Server 2022 10.0.20348.350 Windows Server 2019 (Server Core installation) 10.0.17763.2300 Windows Server 2019 10.0.17763.2300 Windows Server 2016 (Server Core installation) 10.0.14393.4770 Windows Server 2016 10.0.14393.4770