CVE-2021-26443: Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.350Patch KB5007205 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1916Patch KB5007189 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2300Patch KB5007206 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.318Patch KB5007215
Event History
Frequently Asked Questions
What is CVE-2021-26443?
CVE-2021-26443 is a Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability.
Which software versions are affected by CVE-2021-26443?
CVE-2021-26443 affects Microsoft Windows 10 versions 20H2, 21H1, 1809, and 1909, as well as Windows 11 and Windows Server 2016, 2004, 2019, and 2022.
What is the severity of CVE-2021-26443?
CVE-2021-26443 has a severity value of 9, indicating a critical vulnerability.
How can I fix CVE-2021-26443?
To fix CVE-2021-26443, apply the necessary security updates provided by Microsoft.
Where can I find more information about CVE-2021-26443?
You can find more information about CVE-2021-26443 on the Microsoft Security Guidance Advisory page: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26443