Junglewise Threat Intelligence

CVE-2021-42278: Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

CVE-2021-42278 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-04-11

Technologies: Microsoft Windows Server 2008, Microsoft Windows Server 2022, Microsoft Windows Server 2016, Microsoft Active Directory, Microsoft Windows Server 2019, Microsoft Windows Server 2012. Vendors: Microsoft.

Executive brief

Microsoft Active Directory Domain Services contains an elevation of privilege vulnerability. An authenticated attacker can exploit this flaw to escalate privileges within a domain environment. This vulnerability has been observed being exploited in the wild.

Affected products

  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016 up to (excluding) 10.0.14393.4770
  • Microsoft Windows Server 2019 up to (excluding) 10.0.17763.2300
  • Microsoft Windows Server 2022 up to (excluding) 10.0.20348.350
  • Microsoft Windows Server 2004 up to (excluding) 10.0.19041.1348
  • Microsoft Windows Server 20H2 up to (excluding) 10.0.19042.1348

Timeline

  • 2021-11-09: disclosed: NVD Published Date
  • 2022-04-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-02: patched: Due date for remediation per CISA BOD 22-01

Related threats