CVE-2021-36942HIGH
Microsoft Windows Server 2008 R2 Service Pack 1 — Windows LSA Spoofing Vulnerability
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .6602 99.2 YES
AFFECTED Product Versions Fixed Windows Server 2008 R2 Service Pack 1 6.1.7601.0 – — Windows Server 2008 R2 Service Pack 1 (Server Core installation) 6.1.7601.0 – — Windows Server 2008 Service Pack 2 6.0.6003.0 – — Windows Server 2008 Service Pack 2 (Server Core installation) 6.0.6003.0 – — Windows Server 2012 6.2.9200.0 – — Windows Server 2012 (Server Core installation) 6.2.9200.0 – — Windows Server 2012 R2 6.3.9600.0 – — Windows Server 2012 R2 (Server Core installation) 6.3.9600.0 – — Windows Server 2016 10.0.14393.0 – — Windows Server 2016 (Server Core installation) 10.0.14393.0 – — + 4 more
TIMELINE Jul 19 Reserved by microsoft Nov 3 Added to CISA KEV, remediation due 2021-11-17 Nov 3 Published (CNA: microsoft) Aug 10 EXPLOIT PUBLISHED — CVE-2021-36942 (Microsoft Windows Server 2008 R2 Service Pack 1). Public exploit reference added.
CNA: microsoft · CVSS v3.1 · 4 references · NVD status: Analyzed · KEV due November 17, 2021