CVE-2021-26860: Windows App-V Overlay Filter Elevation of Privilege Vulnerability
Published Mar 9, 2021
·Updated
Windows App-V Overlay Filter Elevation of Privilege Vulnerability
Affected Software
24 affected componentsFixes available
Microsoft Windows 10=20h2
Microsoft Windows 10=1809
Microsoft Windows 10=1909
Microsoft Windows 10=2004
Microsoft Windows Server 2016=20h2
Microsoft Windows Server 2016=1909
Microsoft Windows Server 2016=2004
Microsoft Windows Server 2019
Microsoft Windows 10=20H2
10.0.19043.867
Microsoft Windows 10=1909
10.0.18363.1440
Microsoft Windows Server=20H2
10.0.19043.867
Microsoft Windows 10=1909
10.0.18363.1440
Microsoft Windows 10=20H2
10.0.19043.867
Microsoft Windows 10=2004
10.0.19043.867
Microsoft Windows 10=1909
10.0.18363.1440
Microsoft Windows Server=2004
10.0.19043.867
Microsoft Windows 10=2004
10.0.19043.867
Microsoft Windows Server=1909
10.0.18363.1440
Microsoft Windows 10=2004
10.0.19043.867
Microsoft Windows 10=1809
10.0.17763.1817
Microsoft Windows 10=1809
10.0.17763.1817
Microsoft Windows 10=1809
10.0.17763.1817
Microsoft Windows Server 2019<10.0.17763.1817
10.0.17763.1817
Microsoft Windows Server 2019<10.0.17763.1817
10.0.17763.1817
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.867Patch KB5000802 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1440Patch KB5000808 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.1817Patch KB5000822
Event History
Mar 9, 2021
CVE Published
via Microsoft·04:00 PM
Data Sourced
via Microsoft·04:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·04:00 PM
Affected Software
Updated
via Microsoft·04:00 PM
Description
Mar 11, 2021
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
DescriptionSeverity
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this vulnerability?
An attacker needs local access and low privileges on an affected system. No user interaction is required.
2
What is the potential impact if exploitation succeeds?
Successful exploitation can result in elevation of privilege with high impact to confidentiality, integrity, and availability.
3
Which systems should be assessed?
Assess Microsoft Windows 10, Windows Server 2016, and Windows Server 2019 systems, particularly those using the Windows App-V Overlay Filter.