First published: Tue Aug 10 2021(Updated: )
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
=20H2 | ||
=20H2 | ||
=20H2 | ||
=20H2 | ||
=21H1 | ||
=21H1 | ||
=21H1 | ||
=2004 | ||
=2004 | ||
=2004 | ||
=2004 | ||
=20h2 | ||
=21h1 | ||
=2004 | ||
=20h2 | ||
=2004 | ||
Microsoft Windows 10 | =20h2 | |
Microsoft Windows 10 | =21h1 | |
Microsoft Windows 10 | =2004 | |
Microsoft Windows Server 2016 | =20h2 | |
Microsoft Windows Server 2016 | =2004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26431 is classified as a medium severity vulnerability that allows an elevation of privilege in the Windows Recovery Environment.
To fix CVE-2021-26431, install the latest security updates provided by Microsoft for affected Windows versions.
CVE-2021-26431 affects Windows 10 and Windows Server versions 2004, 20H2, and 21H1.
CVE-2021-26431 cannot be exploited remotely; an attacker must have physical access to the affected system.
Exploitation of CVE-2021-26431 could allow an attacker to gain elevated privileges and execute arbitrary code with higher permissions.