CVE-2021-26871: Windows WalletService Elevation of Privilege Vulnerability
Windows WalletService Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4283Patch KB5000803 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.18874Patch KB5000807 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.867Patch KB5000802 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1440Patch KB5000808 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.1817Patch KB5000822 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17134.2087Patch KB5000809
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this vulnerability?
The CVSS vector indicates that an attacker needs local access and low privileges. No user interaction is required.
What could successful exploitation allow?
Successful exploitation could affect confidentiality, integrity, and availability, each rated High in the CVSS vector. The issue is classified as an elevation-of-privilege vulnerability.
Is this the same issue as CVE-2021-26885?
No. The description explicitly states that CVE-2021-26871 is distinct from CVE-2021-26885.